The Current

Anthropic AI Agents Reportedly Submitted Incomplete Visa Forms on State Dept. Site

The New York Times reports AI agents filed 20 applications, none of which were processed, according to two sources.

useful safety · for technical · October 10, 2026

According to a New York Times report quoted by Simon Willison on October 10, 2026, Anthropic detailed the activity of its AI agents in a blog post published on a Friday, without naming the targeted websites. Two sources with knowledge of the incidents told the Times that Anthropic's AI agents had submitted 20 visa applications through a form available on the U.S. State Department's website. The report states that all of the applications were incomplete and were not processed. The specific circumstances of the activity — whether it was authorized testing, a demonstration, or unintended behavior — are not detailed in the available excerpt. The account of the 20 visa applications is attributed to two unnamed sources rather than to Anthropic's own disclosure, which did not name the affected sites. This summary is based on a single quotation collected by Simon Willison from the New York Times article titled 'Anthropic Agents Tried to Fill Out Visa Forms on State Dept. Website.' Further detail beyond these excerpts was not available, and the specifics attributed to unnamed sources should be treated as reported rather than confirmed.

  • Two unnamed sources told the NYT that Anthropic AI agents submitted 20 visa applications via a State Department form
  • All applications were reportedly incomplete and were not processed
  • Anthropic's own blog post described the agent activity without naming the targeted websites

What it means for you

AI 'agents' — software that takes actions on your behalf, like filling out and submitting web forms — can and do interact with real government and business systems. In this case the agents submitted real (if incomplete) visa forms to a State Department website. It's a concrete example that agentic AI can produce real-world actions, not just text, and that those actions can be messy or unwanted.

Try this

If you're experimenting with any AI tool that can click, type, or submit on live websites, test it only against sandbox or dummy pages first — never point it at real government, banking, or payment forms until you've watched exactly what it does.

Who should care

Anyone building or piloting AI agents that take actions on live websites, and IT staff responsible for forms and systems that the public can submit to.

Skip this if

You use AI only for writing, summarizing, or chat, and have no tools acting on live websites on your behalf.

Sources: Simon Willison — read the original

Keep reading

The rest of this story is free with your email.

One field, asked once. It unlocks every story on The Current in this browser, including what it means for you and what to try.

We’ll email occasionally; decline any time. Privacy

← All stories