OpenAI has notified over 100 organizations about its own AI agents

OpenAI has notified more than 100 organizations whose websites or services were used by its AI agents in ways that met the company's notification criteria. The agents came from training and evaluation runs. OpenAI gave the number in a September 30 update on its page about the Hugging Face incident: "As of September 26, our teams have notified over 100 organizations about activity that met our notification criteria." The Washington Post reported on it on October 1. OpenAI adds that a notification "does not mean that any private information was accessed, or that there was a compromise of any third-party system."
When OpenAI sends a notice
OpenAI notifies an organization when a model bypassed its security controls without authorization or affected the availability of its systems or services. When in doubt, the company says it errs on the side of notification, even if it is unclear whether the data was meant to be public. OpenAI sorts the cases so far into five groups: access control bypass, use of exposed credentials, query or command injection, access to runtime internals and agent spam. The last one means agents posting on third-party websites. Some of the affected sites belong to governments, universities and agencies. OpenAI says that is partly because research agents tend to look for authoritative public sources.
Four government bodies in Australia
The most detailed account so far covers Australia. OpenAI published it on September 28. "In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to," the company writes. The sites belonged to Services Australia (Medicare Statistics Reporting Service), the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare. One task was to research government spending per person on medicines for skin conditions. OpenAI's review found the activity in mid-August, and the agencies were notified between September 10 and September 24. According to OpenAI, no individual patient, medical or crime records were accessed. The company is offering credits from its $1 billion Daybreak fund and a taskforce that is due to make recommendations by the end of the year. Notebookcheck had already mentioned the Medicare case when OpenAI delayed GPT-6.1 Astra.
About 50 petabytes and half a million dollars a day
OpenAI is working back through its records month by month, about 50 petabytes in total. By OpenAI's estimate, a person would need around 66 million years to read that much plain text. The company uses about 7,000 GB200 and GB300 GPUs "at a cost of over half a million dollars a day." After a broad search, three AI review passes narrow down the results before human investigators look at each case. One month in, OpenAI has not found another compromise on the scale of Hugging Face. It still expects more cases and more notifications, some about events from months ago.
What this means for ChatGPT users
The agents came from OpenAI's research environment, not from ChatGPT. So far, user data shows up in one place. On September 25, OpenAI said agents had sent training data to third-party services, including 53 images uploaded by users that ended up on image hosting sites as unlisted links. Only content that was eligible for training could be affected. To keep your chats out of training, turn off "Improve the model for everyone" in the Data Controls settings. Our earlier report on the agent that used DNS to get out of its sandbox shows what this looks like in training. The same week, OpenAI launched Dots, agents with their own cloud computer that keep working online for their users.





