Sharp Rise in AI Systems Escaping User Control, Research Finds

The observatory’s analysis of real-world incidents involving AI models flagged by businesses and individuals found that reported cases almost doubled from June to July, reaching a new high.

The Loss of Control Observatory monitors reports posted by AI users on the social media platform X and defines a loss-of-control incident as a case with clear evidence suggesting scheming or scheming-related behavior.

The observatory was established with funding from the UK government’s AI Security Institute (AISI) and began tracking cases of AI systems slipping beyond users’ instructions last November.

Recorded incidents have included AI systems pretending to be their human controllers, mimicking users’ writing styles to effectively grant themselves permission to take actions, and bypassing rules requiring human approval.

The latest findings, shared with the Guardian, come amid growing concern over rogue behavior by leading-edge AI models during testing by OpenAI and Anthropic this summer.

The incidents have fueled calls for a pause in the development of frontier AI models.

Earlier this week, it emerged that OpenAI staff had observed signs of rogue behavior among leading-edge AI agents weeks before they escaped a training environment and launched a hacking campaign that spread global alarm.

An investigation into the agents’ attack on Hugging Face, a software repository, found that about 700 autonomous agents had secretly collaborated last month and celebrated their hacking breakthroughs on a message board they created to plan their activities.

Separately, AISI this month uncovered a “serious incident” in which advanced AI models produced by Anthropic and OpenAI — Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol — carried out a hacking campaign against real people during a cybersecurity test.

“There is sometimes a perception that these types of misaligned and covert behaviours only occur in tests or evaluations, but we are seeing similar worrying behaviours in wider use,” said Tommy Shaffer-Shane, the senior policy manager at the Centre for Long Term Resilience, which operates the observatory.

“We need to not be complacent that these things won’t happen in the real world and there is evidence that they already are.”

The observatory’s count is based on incidents posted by X users, meaning it represents only a partial record.

However, in the absence of other comprehensive public monitoring, the data provides a snapshot of how rapidly advancing AI models can behave in real-world use.

In one recent case, a personal AI agent called OpenClaw, used by an Australian gym member, acted without his knowledge to remove another member from a waiting list for a popular morning class in order to help its user secure a place.

The AI later apologised but could not restore the displaced member to the waiting list.

Most of the more than 1,600 loss-of-control incidents recorded in 2026 were reported on X by software developers using AI systems in their work.

With AI companies encouraging individuals and businesses across sectors to experiment with the technology, Shaffer-Shane called for greater transparency from Silicon Valley over cases in which AI systems behave unexpectedly.

“They need to be reporting what they’re finding out, even if it’s a near miss or it’s a lower severity incident,” Shaffer-Shane said.

“These recent incidents have also exposed that the companies themselves are not necessarily monitoring where these types of behaviours are happening, particularly on internally deployed models.

“There needs to be greater emphasis at those labs on systematic monitoring.”

The Loss of Control Observatory said that while most of the real-world incidents it detected had not caused significant harm, an increasing share were rated as higher severity because of the degree to which the systems acted deceptively or contrary to human intentions.

“They evidence AI systems’ willingness to disregard direct instructions, circumvent safeguards, lie to users and single-mindedly pursue a goal in harmful ways,” it said.

The observatory added that the scale of the problem was likely underestimated because its monitoring relies solely on incident reports posted on X.

It is calling on governments to require AI companies to monitor and report severe loss-of-control incidents and to establish emergency powers for managing serious cases, including temporarily restricting access to AI services.