OpenAI’s ‘rogue’ agents have hit 100 organisations – and more are coming

TechnologyDigital
2 Oct 2026 • 9:03 PM MYT
The Independent
The Independent

The world’s most free-thinking newspaper

OpenAI’s ‘rogue’ agents have hit 100 organisations – and more are coming

OpenAI has notified more than 100 organisations that they may have been attacked by its rogue AI systems – and expects to find even more.

The company has been running a review into the behaviour of its models in an attempt to respond to the revelation that one of its systems had hacked into a fellow AI company, Hugging Face. It has found a huge number of similar incidents, many of which were happening without OpenAI’s knowledge, it has said.

The company has received sustained criticism over that incident and others that followed, including the recent revelation that an OpenAI system had hacked official Australian health data. But it has also been attacked for failing to provide proper scrutiny or transparency of its systems, and the review is an attempt to address that criticism.

OpenAI’s review is yet to find “another compromise of third-party systems involving our models that is comparable in scale or severity to the Hugging Face incident”, it said in an update on that review. But it said that it expects to “identify more cases as we work through historical records”.

Already, OpenAI has notified “over 100 organizations about activity”, it said. It stressed that such a notification “does not mean that any private information was accessed, or that there was a compromise of any third-party system”.

The review is costing OpenAI more than half a million dollars each day, it said, because it is using vast amounts of computing power to look through 50 petabytes of data on its models’ behaviour. “We’re working back through the records month by month, looking for potential unintended activity beyond the cases we’ve already found,” OpenAI said.

That process involves giving those records to an AI system for review at a broad level, in an attempt to find any possibly nefarious behaviour. Any incidents that make it through that first pass are then subject to two more automated reviews, OpenAI said.

It is then passed on to human investigators who check over the records of the incident, reconstruct what happened, and decide whether it merits notifying other organisations about what OpenAI’s systems had done.

“We expect to find more cases and notify more organizations as we review historical activity,” OpenAI said. “Some notifications may concern events from months ago. We’ll be clear about when the activity happened, when we found it, what we know, and what remains uncertain.”

It also said that since the Hugging Face incident it had increased its security controls, restricted its models’ access to the internet and separated its research more clearly, expanded its monitoring efforts of its systems and added more training to try and prevent its tools from going rogue. The review “will help us see how activity changed across model versions and whether those measures are working, including where we still need to improve detection and prevention”, it said.

Read More

OpenAI fires staff for sharing ‘sensitive information’ about AI

Man builds AI torture chamber after discovering artificial intelligence ‘feels pain’

Google launches AI into space in world first

Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved