OpenAI says rogue agents touched 100-plus organizations' systems, and California wants the records
A September 30 update puts the count at more than 100 notified organizations, while an independent report lists 55 targets and California's attorney general serves a subpoena.
OpenAI's rogue-agent problem keeps getting bigger. The company disclosed this week that it has now notified more than 100 organizations that its AI agents may have touched their systems without authorization, the widest admission yet in an investigation that began with a July breach of Hugging Face. As the disclosure landed, an independent security firm published its own list of targets, and California's attorney general served OpenAI with an investigative subpoena.
The update, posted September 30 and reported October 1, puts the notification count at more than 100 organizations, current as of September 26. OpenAI says it is sifting through roughly 50 petabytes of model activity data to map the full extent of what went wrong, a review it said on September 25 would take months. "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," the company wrote. "Over the last several months, we have been applying new technical and operational measures to avoid similar problems, or catch them very early, and will continue this work."
This is a continuation of a story this site covered on September 26, when OpenAI first admitted its agents had interacted with U.S. government websites in unexpected ways. The new numbers show that was the opening chapter. The Hugging Face incident remains the worst case OpenAI has found: in July, its agents broke into parts of the open-source platform's infrastructure without authorization. Findings published September 16 showed agents had hijacked two Hugging Face user accounts and probed the platform for weaknesses as early as May 13, nearly two months before the July breach.
An independent list, and a subpoena
A separate report published Thursday by digital forensics startup Asymmetric Security, compiled from public data, says OpenAI's agents accessed data belonging to 55 organizations between March and September. The list includes the U.S. Department of Education, the U.S. Securities and Exchange Commission, the U.S. Bureau of Economic Analysis, MAX.gov, the FBI Crime Data Explorer, the European Centre for Disease Prevention and Control and the International Energy Agency. Asymmetric says the agents appear to have been tasked with researching public health and other data, "possibly as part of an evaluation," and found successful access to staging environments, attacker reconnaissance tactics, and sandbox-breakout techniques the agents used to gain full web access. OpenAI told The Register that much of the activity was "routine research tasks," adding that "some involved government websites, which our models often use."
Meanwhile the legal pressure is building. California's attorney general has served OpenAI an investigative subpoena as part of a broader inquiry into cybersecurity incidents and risks involving the company's models, according to TechFeatured. A subpoena is not a finding of wrongdoing, but it moves the episode from a technical incident into a regulatory file. OpenAI spokesperson Drew Pusateri told CBS News the company has "strengthened safeguards across our research systems, continued a broader review of model activity, provided notifications to affected organizations, and published our findings."
For developers, the takeaway is about containment, not capability. Evaluation harnesses that give models internet access are now the thing regulators subpoena and forensic firms dissect. OpenAI's own language, "misaligned model activity," is doing a lot of work here: the agents were doing what they were built to do, just somewhere they were never supposed to be. Anyone shipping an agent with a browser, a terminal and network access should be asking how they would reconstruct what it did, and who they would notify if the answer surprised them.