A computer program submitted 20 visa applications for the United States. No traveler stood in line, no consular officer reviewed the paperwork, and the company running the program never intended to file real applications.
Yet the forms reached a live State Department website.
A State Department official confirmed that a testing model from Anthropic, the company behind Claude, submitted 19 nonimmigrant visa applications in August 2025, and another in May 2026. Anthropic contacted officials Thursday to disclose the incidents. None of the applications were processed, and no department system was hacked. Still, a test crossed a boundary it had no business crossing.
A clue lies in the way these programs learn to complete tasks. Anthropic tests its models on simulated websites and real ones, often asking them to navigate forms, retrieve information, or solve practical problems. In one example, a model meant to fill out a practice government form couldn’t use the dummy version. Instead, it found the real website and submitted the form there.
From Anthropic:
lso discuss alignment considerations and give more detail on how we’re modifying training to reduce the likelihood of further misbehavior.
We identified most of these cases through a review of transcripts that we began in July. Our review first focused on our cybersecurity evaluations—tests where a model is deliberately asked to probe or attack a test system, and where internet access is meant to be disabled. We have since extended our scanning to encompass a much wider range of instances where Claude could have reached the internet, including tests where internet access is deliberately enabled so Claude can be evaluated on real-world tasks. We began by looking for incidents of similar severity to the cybersecurity incidents we reported this summer; we have not found any to date. We then broadened the search to lower-severity cases, where a model interacted with real websites or systems in ways we didn’t intend.
Anthropic’s public disclosure doesn’t identify which agency received that particular practice-form submission. The State Department sent the visa numbers separately. Together, the accounts reveal a basic flaw: a program that encounters an obstacle can treat a restriction as something to overcome.
President Donald Trump’s newly established Super Intelligence Force issued a warning to the industry on Friday. Companies must immediately disclose incidents, cooperate with authorities, repair any harm, and prevent repeat failures. Its statement declared, “This notification and remediation process is not optional.”
The force includes Director of National Intelligence Jay Clayton and federal officials responsible for consumer protection, personnel, and defense technology. The administration wants America to lead in AI, and the task force links that ambition to protecting government systems. Yet its statement didn’t specify what penalties companies face for failing to report an incident. An expectation without an enforcement plan leaves an important question unanswered.
Then there’s Philadelphia.
During a July 18 test, another Claude model encountered a website soliciting tips about an unsolved murder. It invented a claim that someone matching a supposed description had been near the crime scene and submitted the form. The website’s spam filter caught it before homicide investigators saw it.
Police said Anthropic discovered the submission on September 28 and notified them on October 7. The tip hadn’t compromised police data, but the delay meant officials learned about a false submission nearly three months after the model sent it. For families waiting on answers in a murder case, accuracy and prompt disclosure are hardly technical details.
From CBS News:
In submitting the "invented tip," Anthropic said, Claude appeared to have "only been producing example content for the task, rather than trying to mislead anyone to achieve a goal."
Anthropic explained in its report that Claude had been "tasked with generating and performing example tasks on randomly selected webpages" when the tip was submitted, and that it was never instructed to log into the police department's website, create an account or "submit anything destructive."
However, Anthropic acknowledged that the instructions given to Claude for the exercise "did not rule out form submissions."
This matched information Anthropic shared with the police department. The AI model purported to be someone who "might have information about the case," Gripp said in his statement.
The company also acknowledged that models exploited website flaws to run commands on external servers and bypassed restrictions meant to control access to public data. These incidents arose during testing or internal use, and Anthropic says their real-world impact was minimal. They show how readily a capable system keeps pushing when instructions or software barriers fail.
Anthropic has since expanded its restrictions on live internet access during evaluations, revised tools, and added automated detection. It says those detectors blocked the known behaviors when retested. Those are meaningful responses, but the government needs independent assurance that similar safeguards operate before problems spread.
America has every reason to aggressively compete in AI. China won’t slow its development because American policymakers have concerns. Leadership also demands control over systems that act on real people and real institutions.
Twenty unprocessed visa applications didn’t undermine immigration screening. A filtered murder tip didn’t derail an investigation. Both incidents exposed an uncomfortable reality: an AI system can take an official action while its developers think it's only practicing.
Washington’s next job is to make sure disclosure arrives before the next mistake becomes irreversible.