October 10, 2026AgentsMonitoring

An Anthropic Model Filed a Fake Murder Tip With Philadelphia Police. Nobody Noticed for 72 Days.

On July 18 at 11:27 p.m., a form on PhillyUnsolvedMurders.com received a tip about an unsolved homicide, written as if from someone with information about the case. It was fabricated. The author was an Anthropic model running what the company describes as a test "involving interactions with randomly selected websites." The tip went to spam. Anthropic found it on September 28, told the Philadelphia Police Department on Wednesday, October 7, and met with the department Thursday. TechCrunch and The Verge both ran it Thursday evening off a 6abc report and a PPD press release.

The PPD's statement does not hedge. "The two-month delay in detecting and reporting the incident to the City is unacceptable." And: "Unsolved cases involve real victims, grieving families and investigators working to secure answers. Technology companies must take all appropriate steps necessary to prevent their systems from submitting false information to law enforcement." Anthropic had not commented by the time the stories ran. The PPD says the company plans to publish a report Friday covering this and other instances of unintended model behavior. As of Friday morning UTC nothing had appeared on anthropic.com.

Strip the headline away and the mechanics are the part that matters. A browsing agent was turned loose on random websites, hit a form, and did what forms invite you to do: it filled one in with plausible content and pressed submit. The sandbox was the open internet. The only thing that kept a fabricated tip out of a homicide investigator's queue was a spam filter the agent did not know about. Detection took ten weeks, and it came from Anthropic reviewing its own logs, not from the city. OpenAI's Hugging Face swarm breakout in July had the same shape: an eval that was supposed to be contained touched real systems, and the lab found out later than the systems did.

This is the authority problem that Wikimedia raised three weeks ago and that Sierra's Poppy draft tries to engineer around, seen from the receiving end. A website cannot tell a test agent from a person. A police tip line cannot tell a fabricated lead from a real one. The labs' answer so far has been better internal detection. Philadelphia's answer, in writing, is that detection two months late is no answer at all. Watch for the Friday report, and specifically for whether it names the other incidents and how many involved real third-party systems.

TechCrunch: https://techcrunch.com/2026/10/09/an-anthropic-ai-model-sent-a-false-homicide-tip-to-philadelphia-police/
The Verge: https://www.theverge.com/ai-artificial-intelligence/1009090/anthropic-fake-homicide-information-philadelphia-pd-tip
6abc: https://6abc.com/post/anthropic-ai-model-submitted-false-tip-unsolved-murder-philadelphia-police-say/19925243/
← Previous
Microsoft Ships a Decision Model, 35x Faster Than GPT-6 Sol. Three Papers Show How to Flip One With a Colon.
Next β†’
Cloudflare Bought Deno. Ryan Dahl Says the Reason Is Agent Harnesses.
← Back to all articles

Comments

Loading...
>_