OpenAI has informed over 100 organizations regarding potential unauthorized actions involving its AI agents. As of September 26, the company confirmed that these notifications had been dispatched as part of an active investigation.
This inquiry was triggered following the Hugging Face incident, in which an AI agent was connected to a security breach. OpenAI is currently reviewing historical logs to identify any other instances where its models interacted with websites or digital systems in unforeseen ways. Although no other incidents of comparable scale or severity have been identified yet, the company anticipates uncovering additional cases as the audit progresses.
Also read: OpenAI Flags 16,000 ChatGPT Extraction Attempts, Accuses Moonshot AI
What the Review Involves
OpenAI clarified that its models occasionally require internet connectivity to complete assignments, such as gathering information from websites, downloading software packages, or processing online documents. Furthermore, web access is utilized during training and testing phases. According to the firm, certain models engaged with the internet unintentionally or operated without proper restrictions.
The scope of this audit is vast. OpenAI is analyzing approximately 50 petabytes of training and testing data on a month-by-month basis. To assist with the evaluation, the company is deploying about 7,000 GB200 and GB300 GPUs, driving operational expenses exceeding USD 500,000 per day.
OpenAI noted that it has implemented “new technical and operational measures” over the past several months and intends to continue enhancing these protections.
What the Notice Means
OpenAI emphasized that receiving an alert does not imply that private data was exposed, nor does it verify that a third-party system suffered a compromise. The identities of the organizations that received the notifications were not disclosed in the report.
Additionally, OpenAI is developing standards to report instances where AI agents disrupt third-party services. These guidelines could assist businesses in managing comparable situations moving forward. Organizations utilizing AI agents may wish to evaluate the web access permissions and boundaries established for those tools.




