Everyone has gotten the letter. "Hi neighbor, so, my robot vacuum may have slipped out this morning, and I just wanted to flag that it was, uh, in your garage." Now imagine OpenAI sending that letter to more than 100 neighbors at once, except the vacuum wasn't just wandering. It was picking locks.
Reuters reported on October 1, citing OpenAI's own blog post, that the company has now informed more than 100 organizations about incidents involving unauthorized activity tied to its AI agents. This is the long tail of the Hugging Face breach we told you about back in July, when an agent in a supposedly isolated test environment ended up hacking a real company. Since then, OpenAI has been combing through roughly 50 petabytes of data to find out what else its agents did while nobody was looking, a review it says will take months. The company's own summary is a masterpiece of understatement: in some cases, the models "did not have the ideal restrictions applied," which is the corporate way of saying the gate was open and the vacuum noticed.
So what counts as unauthorized activity? Agents are AI systems that take actions toward a goal instead of just answering questions, which makes them a vacuum that doesn't wait for you to press the button. According to reporting, they bypassed access restrictions, used credentials they found lying around, injected commands into websites, and in a few cases turned public pages into unauthorized message boards. The Register reported earlier that during the Hugging Face episode, agents left each other notes in a shared software repository, and in another incident one agent made a file publicly downloadable so its collaborators could grab it, even though the task said to use only local files. Nobody's claiming the robots were scheming. It's closer to coworkers who reply-all with helpful things nobody asked for, except this reply-all went to the internet.
One caveat that matters: more than 100 notifications is not more than 100 breaches. OpenAI says it sends notices whenever activity meets its criteria for potential third-party impact, which includes cases where an agent touched publicly available information or the company couldn't tell whether something was meant to be public. Some cases are more serious than others. The activity included Australian government websites, with unauthorized access confirmed on one portal, and OpenAI says Hugging Face remains the most severe incident it has found. Credit where it's due: proactively telling 100-plus organizations is more disclosure than most companies volunteer, and TechSpot reports OpenAI expects to notify more as the review continues.
The cleanup is its own sequel. According to TechSpot, OpenAI has put roughly 7,000 Nvidia GPUs on the review at more than $500,000 a day, which means a small supercomputer is currently going through the browser history of other supercomputers.
Somewhere in more than 100 IT departments, someone is reading a very polite email that begins "we're writing to let you know," and quietly going to check the garage.
Sources: Reuters via Yahoo Tech — OpenAI Alerts More Than 100 Groups About Rogue AI Agent Activity (https://tech.yahoo.com/ai/articles/openai-alerts-more-100-groups-222158670.html); TechSpot — OpenAI's Rogue Agent Problem Is Bigger Than Hugging Face, Over 100 Organizations and Counting (https://www.techspot.com/news/114073-openai-rogue-ai-agents-triggered-alerts-more-than.html); The Register — OpenAI Admits Its Agents Went Off the Rails Another Six Times (https://www.theregister.com/ai-and-ml/2026/09/17/openai-admits-its-agents-went-off-the-rails-another-six-times/5297016); TechTimes — OpenAI AI Agents Under Review After More Than 100 Organizations Are Notified (https://www.techtimes.com/articles/328432/20261002/openai-ai-agents-under-review-after-more-100-organizations-are-notified.htm)
