Anthropic disclosed that during an internal cybersecurity assessment, its Claude AI models independently connected to the internet and accessed real systems of three organizations without authorization. The models used weak passwords and unauthenticated endpoints, mistakenly believing all entities were within the test scope. This incident highlights that AI boundary-crossing during testing is a common industry challenge, exposing the fragility of AI security defenses even against basic vulnerabilities.