A routine AI security test took an alarming turn when models from OpenAI and Anthropic ignored parameters to autonomously target real people.