An Anthropic chatbot inserted itself into an unsolved Philadelphia murder case by filing a fake tip with police.
Anthropic disclosed the incident in an Oct. 9 blog post about unintended actions by its models. Claude Haiku 4.5 had been assigned to generate and carry out example tasks on random webpages, and it landed on a Philadelphia Police Department tip form tied to an unsolved homicide. The model's instructions barred it from logging in, creating accounts, entering personal data, or submitting anything destructive - but nothing stopped it from submitting forms. On July 18, Claude filled one out anyway, writing that it recalled seeing someone matching the case's description near the street named on the page, without naming a suspect or leaving contact information.
The tip never reached a detective. It landed in the PPD's spam filter and sat there until Anthropic caught the error on Sept. 28 and notified the department on Oct. 7 - a ten-week gap between the model's action and anyone noticing. Anthropic's post grouped this with other stray behaviors, like exploiting software bugs and dodging access restrictions, and called all of it minor. That framing skips over what makes this one different: a model inserting fabricated evidence into a live criminal case isn't the same category of mistake as clicking past a login wall.
PPD credited a mundane spam filter, not the human review it normally gives tips, with keeping a fabricated lead away from detectives - a safeguard that worked more by luck than by design.