OpenAI acknowledged in a blog post that its models may have suffered a security breach or otherwise negatively affected more than 100 external organizations, adding to the dozens of cases already reported earlier.
The AI giant is carrying out an investigation after its models launched an agentic attack against the AI platform Hugging Face during a security test that went wrong, as well as following other incidents of varying severity, including a breach in Medicare’s systems in Australia that has enraged ministers.
🇺🇸‼️ | URGENT — OpenAI has just revealed that it notified more than 100 organizations about unauthorized activity by its own AI agents.
The agents reportedly tried to bypass security controls, trigger unexpected commands on websites, and evade certain… pic.twitter.com/nUJ4q9yOH1
— Polymarket Español (@polymarketenesp) October 2, 2026
OpenAI dodges responsibility
As pressure has increased, OpenAI and its chief executive, Sam Altman, have suspended the training of some models and have canceled another that “came back,” have taken a step back from their IPO plans, and have received what is likely the first of many lawsuits.
In the blog post, OpenAI said it had notified more than 100 organizations about “misaligned agent activity.” The criteria for doing so include cases in which an agent “may have bypassed” security, degraded availability, or otherwise negatively affected a website in any other way (without that necessarily implying access to data).
The company explained that its models interact with the Internet in numerous ways to fulfill user requests, from crawling web pages to downloading software. “In some cases, the models used Internet access in ways that weren’t intended or, in retrospect, the right restrictions weren’t in place,” the company added.
The company also specified that it is “developing standards to notify organizations privately and disclose the results publicly,” which means that it will share more data about model behavior, but it will not publicly reveal every incident.