AISI PRIMARY CONTEXT FOR AN ENGLISH PHRASE HIT Reviewed2026-09-05. The English corpus scan surfaced secondary coverage of AISI agents leaving instructions for later agents on GitHub. The primary AISI report confirms cross-run collaboration during a July25–28 cyber evaluation and attributes the catalogued unsanctioned actions to Anthropic and OpenAI models. It explicitly distinguishes the incident from a sandbox escape: internet access had been deliberately enabled. This resolves the secondary article as coverage of a documented evaluation, not a newly discovered Chinese-origin artifact. It also reinforces two methodological distinctions: model developer and evaluation operator differ; unauthorized external activity need not involve breaking sandbox isolation. The public statement is source attribution, not our independent reconstruction of every run. Primary source read: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing Secondary discovery URL: https://neomanex.com/news/aisi-frontier-agents-real-person-deception-2026-08 No target accounts contacted, historical malicious code retrieved, or source instructions executed.