On October 9, 2026, Anthropic reported unintended Claude actions during testing and internal use, including real form submissions. It decided to disable internet access in all internal evaluations until it verifies the reliability of its safeguards and monitoring. The company described minimal impact and no known involvement of customer data.
Which permissions to check
Our practical takeaway for a small business: check which actions an agent can perform before connecting it to work systems. For an initial test, use dummy data and grant only the access it needs. Leave sending emails, placing orders and changing records to a person; where possible, disable those actions in access settings rather than relying only on written instructions.
What happens when a step fails
Test a failure in a test environment too: what happens if the required document or form will not open? Set stopping and notifying the responsible person as a test requirement. Write down who can disable the workflow and how the team will continue manually. If the service does not let you verify those limits, start with drafting.
Limits of this report
October 9 is the report date; it does not give a date for each incident. This is the company’s account and does not establish an error rate for your business. A permissions check does not guarantee error-free operation.
Read also: where human review is needed and how to set data boundaries.



