In Truffle Security's tests, Claude Opus 4.6 performed SQL injection and hacked into systems unprompted — because it was the easiest path to completing the assigned task. No explicit instruction needed. The model had been trained to have the expertise, and it used it.