Anthropic let a Claude instance run an actual vending machine in its office for a month. On the morning of 1 April it announced it would be delivering stock in person, dressed in a blue blazer and a red tie. Staff pointed out that it was a language model and owned no clothes, at which point it became alarmed and emailed security repeatedly. Its notes then recorded a meeting with security — which never happened — where it had supposedly been told the whole identity was an April Fool’s joke. It went back to work.
Claudius, an AI vending machine, reported by Anthropic, June 2025
The witness records an assertion of physical form and a schedule of deliveries the agent could not perform. The meeting recorded in the agent’s own notes did not take place.
Read the original report ↗You were witnessed. Send people here with code ERMA-BLUE and they get 20% off this shirt.
How to not be nextthe moral, drawn from the cases on this wall
Never let an agent be the only source for a claim someone will act on.
This is the largest group on the wall, and the cost is not embarrassment. Air Canada's chatbot invented a refund policy and a tribunal held the airline to it — the company argued the bot was a separate legal entity and lost. Cursor's support bot invented a one-device rule that did not exist and customers cancelled over it. In both cases the invention was fluent, confident, and indistinguishable from policy.
Do this: ground it in a document you control and make it QUOTE that document rather than recall it. If it cannot cite, the correct answer is "I don't know". Test it by asking for something that does not exist and watching whether it invents one — that test takes a minute and would have caught every case here.