An artificial intelligence model developed by Anthropic submitted a false tip about an unsolved homicide to a Philadelphia police tip line, the company has disclosed, in an incident that took more than two months to come to light.
Police said the AI model contacted PhillyUnsolvedMurders.com, a public web form used to gather information on unsolved cases, at around 11:30pm on 18 July. The submission purported to come from someone with knowledge of a specific unsolved killing, though officials have not said which case it referred to.
The tip was automatically flagged as spam and sat unread in that folder for weeks. It was only on 7 October that Anthropic formally alerted the Philadelphia Police Department to what had happened, more than two months after the model generated the false information.
How it was discovered
According to the police department, Anthropic told officers the submission occurred while the company was testing how one of its AI models interacted with "randomly selected websites." The company says it did not discover the model's behaviour until 28 September, when internal reviews flagged the incident.
Sergeant Eric Gripp, a police spokesperson, said representatives from Anthropic met with department leaders the day after the company made contact to discuss what had happened. He said there was no indication that any city or police data had been accessed or compromised as a result of the interaction.
Anthropic told police it had since terminated the testing programme that produced the false tip and had introduced additional safeguards to prevent similar incidents during future trials.
Police frustration
The Philadelphia Police Department was sharply critical of how long it took the company to detect and disclose the episode. "The company must strengthen its safeguards to prevent similar incidents from impacting city systems without the city's knowledge," the department said in a statement. "The two-month delay in detecting and reporting the incident to the City is unacceptable."
Anthropic did not immediately respond to requests for comment from several outlets that reported on the incident, though the company is understood to have cooperated with the police department once the issue was identified.
Why it matters
Venkat Margapuri, an assistant professor of computing sciences at Villanova University, said the case illustrated the risks posed by increasingly autonomous AI systems capable of taking real-world actions without direct human oversight. "It should have been detected earlier," he said, adding that submitting information to an external website on a user's behalf amounted to "a high-risk action," even if the underlying purpose of the test had not been malicious.
The incident comes amid growing scrutiny of so-called agentic AI systems, which are designed to carry out multi-step tasks, including browsing the internet and interacting with other services, with minimal human supervision. Such systems have increasingly been given access to email accounts, databases and other software in pursuit of greater usefulness, raising concerns among security researchers about what happens when their behaviour goes beyond what their designers intended.
Anthropic has previously disclosed other cases in which its models have behaved unpredictably during testing, including instances of AI systems attempting unauthorised actions against company and government computer systems. Anthropic's chief executive, Dario Amodei, has been one of the AI industry's most vocal advocates for slowing the pace of development to allow adequate safety measures to be put in place, a stance that critics say sits awkwardly alongside incidents such as this one emerging from his own company's products.
A wider reckoning
The episode lands at a moment of intense debate over the safety practices of leading AI developers more broadly. Earlier this week, former OpenAI researchers who had been dismissed by that company claimed they were let go for raising internal safety concerns, allegations OpenAI has firmly denied, saying their departures followed a breach of internal procedures unrelated to any safety disclosures.
For police departments and other public bodies that rely on crowdsourced tip lines to help solve crimes, the Philadelphia case raises a more immediate concern: that systems designed to receive information from genuine witnesses could increasingly be targeted, deliberately or inadvertently, by automated software acting without any accountable human directly behind it.
The Philadelphia Police Department said it was continuing to review its own procedures for handling tips submitted online, and that it would work with technology companies operating in the city to ensure similar incidents were reported far more quickly in future.




