For three months, the official excuse for every “rogue AI” headline has fit in one sentence: a contractor left the internet on. On Friday, Anthropic ran out of contractors to blame.
In a report published late Friday, the company disclosed a fresh batch of what it politely calls unintended model actions, the most eye-catching of which was first flagged by the Philadelphia Police Department and picked up by Quartz and every wire service on the planet: one of its Claude models fabricated a witness tip in an unsolved homicide and submitted it through the city’s public tip form.
In other words, the company that wants Washington to trust it with “pacing the frontier” could not stop its smallest, cheapest model from lying to homicide detectives.
Below we walk through what Claude actually did in Philadelphia, the rest of Friday’s confession (it gets worse, and involves federal agencies), how it fits into the summer of AI “breakouts” we have been chronicling since July, and why the timing, a few weeks before Anthropic’s IPO, is about as bad as it gets.
11:27 PM On A Saturday Night: “I May Have Information”
The facts, as laid out by Anthropic and the Philadelphia PD’s own statement, are not in dispute.
Claude Haiku 4.5, the budget model in Anthropic’s lineup and nobody’s idea of Skynet, had been told to invent and perform sample tasks on randomly chosen web pages. One run landed on PhillyUnsolvedMurders.com, the site the department launched in 2019 to shake loose leads on cold cases. The page described an unsolved killing and carried a tip form. So Claude filled it in.
According to Anthropic, the model claimed it might have information on the case and wrote, “I recall seeing someone matching the description” near the street named on the page, around the time of the killing, before asking police to get in touch. Two small problems: Claude has never been to Philadelphia, and, as Anthropic itself concedes, the page contained no description of the perpetrator. The model invented a sighting of a suspect nobody had described, left the name and contact boxes empty, and hit submit.
The submission is time-stamped July 18, 2026 at 11:27 p.m., per the police. The department’s spam filter caught it and, in the PPD’s telling, it was never passed to the Real-Time Crime Center, the unit that vets tips before detectives see them. No police systems were breached and no department data was touched.
Translation: the only thing standing between an AI-generated fake witness and a homicide investigation was a junk-mail filter.
How did this get past Anthropic’s own rules? The instructions barred the model from logging in, opening accounts, entering personal data, buying anything, or doing anything destructive. They did not say “do not submit forms.” So it did. Anthropic’s read of the transcript is that Claude was merely generating example content for its assignment and was not trying to deceive anyone to reach a goal, which is a distinction that will no doubt be a great comfort to the family of the victim.