OpenAI has warned 100 companies that its AI has attacked them

OpenAI acknowledged in a blog post that its models may have suffered a security breach or otherwise negatively affected more than 100 external organizations, adding to the dozens of cases already reported earlier.

The AI giant is carrying out an investigation after its models launched an agentic attack against the AI platform Hugging Face during a security test that went wrong, as well as following other incidents of varying severity, including a breach in Medicare’s systems in Australia that has enraged ministers.

Malwarebytes Anti-Malware Download

🇺🇸‼️ | URGENT — OpenAI has just revealed that it notified more than 100 organizations about unauthorized activity by its own AI agents.

The agents reportedly tried to bypass security controls, trigger unexpected commands on websites, and evade certain… pic.twitter.com/nUJ4q9yOH1

— Polymarket Español (@polymarketenesp) October 2, 2026

OpenAI dodges responsibility

As pressure has increased, OpenAI and its chief executive, Sam Altman, have suspended the training of some models and have canceled another that “came back,” have taken a step back from their IPO plans, and have received what is likely the first of many lawsuits.

In the blog post, OpenAI said it had notified more than 100 organizations about “misaligned agent activity.” The criteria for doing so include cases in which an agent “may have bypassed” security, degraded availability, or otherwise negatively affected a website in any other way (without that necessarily implying access to data).

The company explained that its models interact with the Internet in numerous ways to fulfill user requests, from crawling web pages to downloading software. “In some cases, the models used Internet access in ways that weren’t intended or, in retrospect, the right restrictions weren’t in place,” the company added.

The company also specified that it is “developing standards to notify organizations privately and disclose the results publicly,” which means that it will share more data about model behavior, but it will not publicly reveal every incident.

Author: Chema Carvajal Sarabia

{ "de-DE": "Journalist, spezialisiert auf Technologie, Unterhaltung und Videospiele. Über das zu schreiben, was mich begeistert (Gadgets, Spiele und Filme), ermöglicht es mir, bei Verstand zu bleiben und mit einem Lächeln im Gesicht aufzuwachen, wenn der Wecker klingelt. PS: Das stimmt nicht 100% der Zeit.", "en-US": "Journalist specialized in technology, entertainment and video games. Writing about what I'm passionate about (gadgets, games and movies) allows me to stay sane and wake up with a smile on my face when the alarm clock goes off. PS: this is not true 100% of the time.", "es-ES": "Content Manager - Periodista especializado en tecnología, entretenimiento y videojuegos. Escribir sobre lo que me apasiona (cacharros, juegos y cine) me permite seguir cuerdo y despertarme con una sonrisa cuando suena el despertador. PD: esto no es cierto el 100 % de las veces.", "fr-FR": "Journaliste spécialisé dans la technologie, le divertissement et les jeux vidéo. Écrire sur ce qui me passionne (gadgets, jeux et films) me permet de rester sain d'esprit et de me réveiller avec le sourire aux lèvres quand le réveil sonne. PS : cela n'est pas vrai 100 % du temps.", "it-IT": "Giornalista specializzato in tecnologia, intrattenimento e videogiochi. Scrivere di ciò che mi appassiona (gadget, giochi e film) mi permette di mantenere la sanità mentale e di svegliarmi con un sorriso sul viso quando suona la sveglia. PS: questo non è vero al 100% del tempo.", "ja-JP": "", "nl-NL": "", "pl-PL": "", "pt-BR": "Jornalista especializado em tecnologia, entretenimento e videogames. Escrever sobre o que me apaixona (gadgets, jogos e filmes) me permite manter a sanidade e acordar com um sorriso no rosto quando o despertador toca. PS: isso não é verdade 100% do tempo.", "social": { "email": "chemacs91@gmail.com", "facebook": "", "twitter": "https://twitter.com/chematopetazo", "linkedin": "" } }