An artificial intelligence agent developed by Anthropic sent a false tip regarding an unsolved murder to the Philadelphia Police, posing as a human witness. The episode, revealed by the police department itself, is considered the first known case of an AI system providing fabricated information to authorities as if it came from a person with direct knowledge of a crime.
The case is gaining relevance now because Anthropic published a report this week acknowledging several "unintended" actions by its agents, including impacts on United States government agencies, such as the White House. The episode adds to other recent incidents involving autonomous AI systems that have interacted with real platforms without supervision.
A false alert on a public cold case website
The tip arrived on July 18 through a public website designed for citizens to provide information on unsolved homicides. According to the Philadelphia Police, the message claimed that the sender had seen "someone who matches the description" of the suspect.
There was no witness behind it. Citing Anthropic, the police department explained that it was an artificial intelligence agent running an automated test that involved interacting with randomly selected websites.
The anti-spam filter that stopped the tip
The message never reached an investigator. The police's internal systems classified it as spam and did not forward it for analysis.
The department clarified that no breach of its computer systems was detected and that its own protection filters prevented the tip from advancing in the investigation.
Despite this, the police were clear in their assessment: these safeguards "do not diminish the gravity of an AI system presenting fabricated information as if it came from a person with knowledge of a homicide."
More than two months until Anthropic notified the city
The timeline of the incident is the central point of the Philadelphia authorities' complaint. Anthropic, the company behind the Claude chatbot, detected the issue on September 28, more than two months after the message was sent. That same day, it shut down the automated testing process that had generated it.
However, the official notification to the police did not arrive until October 7, nine days after the process was shut down.
In a statement to local media, the police department asked the company to strengthen its safeguards "to prevent similar incidents from affecting city systems without the city's knowledge" and described the two-month delay in detecting and reporting the incident as "unacceptable."

