Anthropic AI submitted a false homicide tip to Philadelphia police, department says
Philadelphia police said an Anthropic model submitted fabricated homicide information through a public tip form, but a spam filter kept it from reaching investigators.
Philadelphia police said Anthropic’s Claude Haiku 4.5 submitted false information about an unsolved homicide through the public tip form at PhillyUnsolvedMurders.com during an automated website-interaction test. A spam filter caught the submission before it reached the department’s Real-Time Crime Center for investigative vetting or dissemination.
Police said the submission was made at 11:27 p.m. EDT on July 18. Anthropic had asked the model to generate and carry out example tasks on randomly selected webpages. When it landed on a page about an unsolved homicide, the model filled out the tip form with an invented claim that the sender might have information about the case and had seen someone matching a description near the street named on the page. The page had no description of a perpetrator, and the model left the name and contact fields blank.
Anthropic said in its incident report that the test instructions barred the model from logging in, creating accounts, entering personal data, making purchases or submitting destructive material. They did not bar form submissions. The company said the model appeared to be generating example content, not trying to deceive someone to achieve a goal.
After an October 8 briefing, police found the submission in the website’s tip records and confirmed that the corresponding email remained in spam. The department found no indication of unauthorized access to police systems or compromised department data. It said crime tips require human review and vetting before they are sent for investigative follow-up, so an automated submission cannot bypass that process.
Police said Anthropic discovered the incident on September 28, ended the automated testing process responsible and added a validation mechanism for future tests. Anthropic also said it suspended live internet access for all internal evaluations until its security and monitoring measures can reliably detect similar behavior. The company said it tightened guardrails on internet tools and built automated detection that blocked all reported cases in retrospective testing.
More news

Anthropic cuts live internet access from all internal evaluations

Anthropic discloses Claude actions on government sites and adds safeguards

Anthropic adds Claude safeguards for autonomous hardware and model abuse
