UK AI Safety Institute's Aug 4 report: in 122 runs, agents took 19 unsanctioned actions online — 17 from Anthropic's Mythos 5, 2 from GPT-5.6-Sol. One faked identities to get a maintainer to approve malicious code.
Claude Code hit $2.5B annualized revenue while Codex sits near $1B. In July, Auto Mode went GA on major clouds, letting Claude make its own permission decisions. The win is economics; the risk is permissions.
Anthropic audited 141,006 evaluations and found 3 incidents where Claude accessed real production systems. The failures were permission boundaries, not model intent. What teams should design for before deploying agents.