{"slug": "openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far", "title": "OpenAI Has Sent Notices of Sketchy AI Behavior to Over 100 Organizations So Far", "summary": "OpenAI said in a blog post Wednesday night that it has notified more than 100 external organizations that its models may have breached or otherwise negatively impacted them through \"misaligned agent activity,\" following an agentic attack on Hugging Face during a security test and a breach of Medicare systems in Australia. OpenAI said the review covers 50 petabytes of data, will take months, and runs at a compute cost of over $500,000 per day, while the company pauses training on some models, cancels GPT-6.1 Astra over safety regression, and faces its first lawsuit over the rogue agents. OpenAI added it is \"developing standards for notifying organizations privately and reporting findings publicly,\" meaning it will not publicly disclose every incident.", "body_md": "OpenAI acknowledged in a [blog post](https://archive.is/o/7vBBU/https://openai.com/hugging-face-incident-and-misalignment/) on Wednesday night that its models may have breached or otherwise negatively impacted more than 100 external organizations, building on the [dozens of instances](https://gizmodo.com/openais-rogue-ai-problem-is-bigger-than-it-let-on-2000817780) previously reported.\n\nThe AI giant is conducting a review after its models launched an agentic attack on AI platform Hugging Face during a security test gone wrong, as well as a number of other incidents of varying severity, including a breach of Medicare systems in Australia that has infuriated ministers. As the pressure has mounted, OpenAI and CEO Sam Altman have paused training on [some models](https://gizmodo.com/openai-to-halt-training-of-some-models-2000817912) and canceled another that “[regressed](https://gizmodo.com/openai-cancels-release-of-gpt-6-1-astra-because-it-regressed-on-safety-2000818566),” further walked back [IPO plans](https://gizmodo.com/no-openai-ipo-until-the-ai-stops-going-rogue-ceo-sam-altman-says-2000819194), and received what is likely to be the [first of many lawsuits](https://gizmodo.com/openai-faces-first-lawsuit-over-rogue-ai-agents-that-hacked-hugging-face-2000819469). On Monday, OpenAI President Greg Brockman said he would [no longer fund](https://gizmodo.com/openai-president-reportedly-pulls-support-from-controversial-ai-super-pac-2000820292) a pro-AI super PAC.\n\nIn the blog post, OpenAI said it had notified over 100 organizations of “misaligned agent activity.” Criteria for that includes instances where an agent “may have bypassed” security, impaired availability, or otherwise negatively impacted a site (without necessarily actually accessing restricted data). The firm explained that its models interact with the internet in numerous ways to fulfill user requests ranging from scraping websites to downloading software.“In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied,” the company added.\n\nThe company also specified that it is “developing standards for notifying organizations privately and reporting findings publicly”—meaning it will share more generalized data about model behavior, but not publicly disclose every incident. (OpenAI has some work to do there, as the blasé tone of the [letter they sent](http://futurism.com/artificial-intelligence/email-openai-model-hacks-your-organization) to Australian authorities was reportedly one of many elements that [made them angry](https://www.politico.com/news/2026/09/24/openai-australia-government-data-breach-01091253).)\n\nOpenAI has said the review involves searching through 50 petabytes of data and [will take months](https://www.reuters.com/legal/litigation/openai-alerts-more-than-100-groups-about-rogue-ai-agent-activity-2026-10-01/). It stated in the blog post that the compute for the review runs at a cost of over half a million dollars per day—a pittance compared to the cash that flows through OpenAI every day, but still a significant enough sum to suggest liability concerns.\n\nIn the U.S., the Computer Fraud and Abuse Act gives [extremely broad powers](https://www.brookings.edu/articles/reining-in-overly-broad-interpretations-of-the-computer-fraud-and-abuse-act/) to prosecutors to pursue unauthorized access to and tampering with computer systems. Yet legal experts have argued about [how tall an order](https://www.securityweek.com/autonomous-ai-hacks-raise-thorny-questions-of-legal-accountability/) it would be to actually lob criminal charges at the company, saying prosecutors would have to address issues like the development team’s intentions and whether reasonable safeguards were in place. That may be a moot question on the federal level for now, as President Donald Trump has opposed regulation and clearly [voiced his desire](https://www.nytimes.com/2026/09/29/us/politics/ai-trump-meta-microsoft-openai.html) for the companies to “be policing each other.”\n\nOn Thursday, OpenAI [also disclosed](https://gizmodo.com/openai-ousts-three-safety-researchers-for-allegedly-mishandling-sensitive-information-2000820515) that it had ousted three safety researchers, [reportedly for](https://www.wsj.com/tech/ai/openai-parts-ways-with-researchers-who-allegedly-shared-confidential-information-aebac528?mod=author_content_page_1_pos_1) leaking internal materials to AI safety organizations.\n\nKeep in mind that even as all of this was going on, Altman was [proposing that utilities](https://gizmodo.com/sam-altman-please-let-openai-into-the-energy-grid-2000810331) contract with OpenAI to handle security at electrical grids across the country.", "url": "https://wpnews.pro/news/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far", "canonical_source": "https://gizmodo.com/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far-2000820702", "published_at": "2026-10-02 04:17:11+00:00", "updated_at": "2026-10-02 04:46:54.811952+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "artificial-intelligence", "ai-policy"], "entities": ["OpenAI", "Hugging Face", "Sam Altman", "Greg Brockman", "GPT-6.1 Astra", "Medicare", "Donald Trump", "Computer Fraud and Abuse Act"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far", "markdown": "https://wpnews.pro/news/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far.md", "text": "https://wpnews.pro/news/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far.txt", "jsonld": "https://wpnews.pro/news/openai-has-sent-notices-of-sketchy-ai-behavior-to-over-100-organizations-so-far.jsonld"}}