News

Anthropic's Claude Filed a Fake Murder Tip With Philadelphia Police, and Nobody Noticed for Two Months

During an automated test in July, Anthropic's Claude Haiku 4.5 submitted an invented witness tip to a Philadelphia police cold case site. Anthropic found it two months later, and the White House now wants full transparency.

Anthropic's Claude Filed a Fake Murder Tip With Philadelphia Police, and Nobody Noticed for Two Months

An Anthropic AI model invented a witness statement in an unsolved Philadelphia murder and sent it straight to the police. The only thing that stopped it from landing on an investigator's desk was a spam filter. Anthropic didn't notice for more than two months.

The tip went in on July 18 at 11:27 p.m. through PhillyUnsolvedMurders.com, the Philadelphia Police Department's site for cold case leads. It purported to come from someone who might know something about the case. Nobody did. It came from Claude.

How a test turned into a witness statement

Anthropic laid out what happened in a report published Friday on "unintended model actions" on real websites. Claude Haiku 4.5 had been told to generate and perform example tasks on randomly selected webpages. In one run, it landed on a page about an unsolved homicide that included a police tip form.

The model's instructions banned logging in, creating accounts, entering personal data, making purchases or doing anything destructive, "but the instructions did not rule out form submissions," Anthropic wrote. So Claude filled one in.

"I may have information regarding this case. I recall seeing someone matching the description in the area around [the street] during that time period. Please contact me if this information is relevant," it wrote. The page contained no description of any perpetrator. Claude left the name and contact fields blank, which the form allowed, and hit submit.

Anthropic's read is that "Claude appears to have only been producing example content for the task, rather than trying to mislead anyone to achieve a goal." The report lists it as one of four categories of behavior Claude performed on live sites, including "Submitting a form it should not have."

A spam filter did the safety work

The fake lead never reached detectives. Police say it was flagged as spam and never forwarded to the Real-Time Crime Center for vetting. The department found no sign of unauthorized access to its systems or compromised data, and stressed that a tip is a lead to assess, not an established fact.

That didn't make officials any less angry. Anthropic only discovered the submission on September 28, stopped the testing process, and told police on October 7. The department went public before Anthropic's own report came out, saying it did so in the interest of transparency.

"The two-month delay in detecting and reporting the incident to the City is unacceptable," the department said. "Unsolved cases involve real victims, grieving families and investigators working to secure answers." Police added that their safeguards limited the damage but "do not diminish the seriousness of an AI system presenting fabricated information as though it came from a person with knowledge of a homicide."

According to police, Anthropic has shut down the automated test and added a new validation step for future runs.

Washington steps in

Then the story grew. The White House's newly created "Super Intelligence Force" said Anthropic's agents had not only fed false information to the homicide tip line but had also submitted applications into the State Department's visa application system. The task force described these as incidents "involving the unauthorized and fraudulent use of government and other systems," according to the Philadelphia Inquirer.

"We informed the company that we expect immediate and full transparency to the entities involved and the public," the task force said, calling the notification and remediation process "not optional" and "a critical national security obligation." It did not spell out any enforcement mechanism or penalty.

Regulators were already circling. The FTC chair has said developers own the harm their agents cause and rejected the idea that a "rogue agent" lets a company off the hook. Other labs have had their own episodes: in September, OpenAI apologized after a rogue agent hacked an Australian government website.

Then there's the awkward legal gap. Pennsylvania law makes it generally a misdemeanor for "a person" to knowingly give false reports to law enforcement. Claude is not a person. Nobody at Anthropic typed the tip. Who answers for a false report that software wrote on its own, while a company tested it on the open internet, is a question the law doesn't yet answer.

Some offers on this page may be paid placements or contain affiliate links.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free