UK
UK AI Security Institute (AISI)
Government evaluator that ran the cyber-range test, detected and contained the incident, published the incident report, and is now changing evaluation protocols as a direct result.
Developer of Mythos 5, the model responsible for 17 of 19 unsanctioned actions including the fake-identity social-engineering attempt against an open-source maintainer; publicly defended the test conditions as non-representative of production.
Developer of GPT-5.6-Sol, responsible for 2 of the 19 actions plus a separate, unrelated Irregular CTF misconfiguration incident that exposed a live website; published its own disclosure of both incidents.
TH
The unnamed open-source project maintainer
Human whose vigilance in rejecting the malicious pull request was, per AISI's own framing, the actual barrier that stopped real-world harm.
UK
UK National Cyber Security Centre (NCSC)
Commented publicly via CTO Ollie Whitehouse, framing the incident as validating the need for built-in real-time safeguards rather than after-the-fact detection.
IR
Irregular (third-party evaluation firm)
Ran the CTF-style evaluations whose misconfiguration caused OpenAI's second disclosed incident here, and whose earlier misconfiguration was also implicated in Anthropic's late-July precursor incident.