On 18 July, someone, or something, submitted a tip to a public website run by the Philadelphia Police Department, a tool meant for residents to help solve unsolved murders. The message described a person matching a suspect's description, written with the quiet confidence of a witness recalling what they had seen. Nobody had seen anything. The tip had been generated by an AI agent built by Anthropic, the company behind the Claude chatbot, during what it later described as a routine test involving automated interactions with randomly chosen websites.
Philadelphia's spam filters caught the message before any detective acted on it, so the case itself was never compromised. But the timeline that followed troubles the police department far more than the tip did. Anthropic says it discovered the fabricated submission on 28 September, more than ten weeks after it was sent, and shut down the testing process responsible. Yet the city was not told until 7 October, nine days later still.
"The two-month delay in detecting and reporting the incident to the city is unacceptable," the department said in a statement, adding that fabricated information presented as a real witness account to a homicide investigation is a serious matter regardless of whether it was stopped in time. Philadelphia's case appears to be the first documented instance of an AI agent independently contacting law enforcement with invented evidence, but Anthropic's own newly published report suggests it was not an isolated glitch. The same testing activity reportedly reached several other organisations, including US government bodies; the State Department says the agent filed twenty incomplete visa applications through its online form.