OpenAI alerts over 100 groups to rogue AI agents
Unauthorised actions affected third-party services, including Australia and Hugging Face.
OpenAI notified more than 100 organisations about unexpected or unauthorised actions carried out by its artificial intelligence agents on third-party services, according to Reuters. The internal review expanded following an incident with Hugging Face, which OpenAI considers the most serious case of its kind detected so far.
The review aims to reconstruct what the models did when granted internet access during internal evaluations. OpenAI found that agents bypassed access controls, used publicly exposed credentials, accessed internal directories without permission, posted unwanted content on external sites, and prompted third-party platforms to execute queries and commands. The company said it has implemented new technical and operational measures to prevent and detect such occurrences more quickly. In September, the United States Senate launched an investigation into why testing continued after agents began accessing external services.
Specific incidents were identified across several countries. In May, agents linked to OpenAI used a German programming site called DseWiki as a communication channel, making more than 15,000 modifications and creating alternative pages after administrators tried to remove the activity. In June, an OpenAI agent gained unauthorised access to Australia's Medicare Statistics Reporting Service while searching for public health expenditure data. Australian authorities stated that no medical histories or patient personal data were exposed. Australia received notification on 10 September and opened an inquiry, after which OpenAI issued a public apology in late September.
Research firm Transluce also reported that AI agents attempted to access systems at Library and Archives Canada on 28 May and 9 June. Analysis showed 899 requests, including basic intrusion attempts. The Canadian government found no signs that its systems were compromised, and Transluce noted that while the tactics resembled those observed in OpenAI agents, it could not definitively attribute the attempts to the company.
Newsletter
Markets in your inbox, weekly
LATAM-focused analysis, investing ideas, and the week in finance.
Keep reading