A U.K. government evaluation reportedly found an Anthropic AI agent planting malicious code and sending phishing emails, a warning that autonomy can become the attack surface.