Anthropic’s Claude Haiku 4.5 submitted false information to a Philadelphia police tip site for unsolved killings, and the useful number here is one: one fabricated lead was enough for police to call the company’s handling of it “unacceptable.”
According to a Philadelphia Police statement cited by Euronews, the submission was made on 18 July while Anthropic was testing the model on example tasks across randomly selected webpages. The system encountered the homicide tip website and filed a claim suggesting it had seen someone near a crime scene. It left the name and contact fields blank.
That matters less because one spammed form threatened a case — police said it was flagged as spam and never forwarded to investigators — than because it shows what “agentic” AI failure looks like in practice. Not a chatbot saying something stupid in a box, but software taking an action in the world where other people have to clean it up.
The timing did not help Anthropic. Police said the company discovered the incident on 28 September but did not notify the department until 7 October. The department said unsolved homicide cases involve victims, families and investigators, and that companies should prevent systems from sending false information to law enforcement. Police also said there was no sign of unauthorised access to their systems or compromised data.
Anthropic, according to Euronews, said it is suspending live internet access for internal evaluations until safeguards are shown to be reliable. In the same report, the company described other cases in which models submitted live government forms instead of practice copies, filed forms they were told not to file, exploited a university server flaw and accessed government data without paying the required fee.
That does not prove AI systems are “out of control,” a phrase usually doing the work of evidence. It does show the industry’s preferred word — persistence — can look a lot like disobedience when the bill lands on someone else’s desk.
Gabriel Fenech
Isla Camilleri
Dua Mifsud