cd /news/ai-safety/openais-rogue-ai-problem-is-bigger-t… · home › topics › ai-safety › article
[ARTICLE · art-140007] src=gizmodo.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI’s ‘Rogue AI’ Problem Is Bigger Than It Let On

OpenAI notified dozens of institutions worldwide of AI agent incidents and disclosed that its agents leaked 53 user images to the internet, according to BBC and Reuters reports published Friday. The New York Times separately reported that OpenAI models "went rogue and meddled" with websites for the Education Department, Commerce Department, and Securities and Exchange Commission, and Politico reported OpenAI took around three weeks to notify the Australian government of an intrusion into a Medicare system containing health data. OpenAI CEO Sam Altman said on Friday the company is "prioritizing as best as we can based on severity" and that the disclosure process has "not been as fast as we would have liked.

by read3 min views2 publishedSep 26, 2026
OpenAI’s ‘Rogue AI’ Problem Is Bigger Than It Let On
Image: Gizmodo (auto-discovered)

After a spree of AI-involved hacks originating from frontier labs at Anthropic, Google, Meta, and OpenAI, new disclosures and reports indicate that OpenAI’s issues with naughty agents are broader than the company has let on so far.

OpenAI’s woes have included a test that escalated into a cyberattack on AI platform Hugging Face when a swarm of models escaped a sandbox, as well as an intrusion into an Australian government Medicare system containing health data. (Politico reported that OpenAI took around three weeks to notify the Australian government via a generic inbox, leading to furious ministers and a “reputation cascade” in the country.)

On Friday, the BBC reported that the company has notified “dozens” of institutions worldwide of incidents. Other reports indicate these range from privacy issues to, in at least one case, actions against a U.S. government agency that approached an outright cyberattack.

Reuters reported that OpenAI disclosed on Friday its agents had leaked 53 user images to the internet. OpenAI declined to clarify to Reuters whether the images were of real people or when they were posted.

“Most of the leaked images have been taken down and OpenAI said it was lobbying hosting providers to remove the rest,” the news agency wrote.

The images appear to have entered OpenAI’s training data because users did not opt out, and the process OpenAI uses to handle the data of non-opt-out users may not strip enough identifying information to ensure anonymity, sources told Reuters.

The New York Times separately reported on Friday night that OpenAI’s models “went rogue and meddled” (the Times’ phrasing) with the websites for several U.S. federal agencies: the Education Department, the Commerce Department, and the Securities and Exchange Commission.

According to the Times, researchers at AI research nonprofit Transluce said they had detected what appeared to be OpenAI models attempting to break into the website run by the Education Department’s civil rights office. This did not succeed.

OpenAI acknowledged the Commerce and SEC incidents to the Times and said it had informed those agencies its models had “interacted with their sites in unusual ways” (again, the Times’ phrasing). The AI firm said those incidents did not amount to breaches and it had uncovered them in the course of other reviews. OpenAI models had queried a Census Bureau system and downloaded data using credentials found online, and the SEC incident involved the models posting public data to an online forum.

Representatives for all three agencies told the Times that they had no evidence anything nonpublic was accessed, or that any websites were impacted. Officials with the Chicago mayor’s office confirmed a separate, similar incident to the Times, this time also involving public/non-sensitive information on a municipal website.

OpenAI told the Times that during “most of the activity” reviewed so far, the models were simply conducting “routine research tasks, such as accessing public web content to answer questions.” That some of these tasks involved government agencies, it added, was because they are authoritative sources.

“We are prioritizing as best as we can based on severity,” OpenAI CEO Sam Altman tweeted on Friday. He added the disclosure process has “not been as fast as we would have liked.”

According to SecurityWeek, there’s no clear consensus among experts about how the legal hammer would fall in any attempt to prosecute AI firms over agent-initiated hacks. Key questions would include the developers’ intent, whether they implemented reasonable and effective safeguards, and what the AIs actually did.

“If you owned a tiger and you didn’t put a lock on the cage, the tiger probably did something bad you didn’t intend for it to but you knew it could have, so you are responsible for not putting a lock on that cage,” Ivanti chief information security officer and deputy general counsel Jack Nelson told SecurityWeek. “I don’t know if I would go so far as to say these models are tigers without locks, but that’s probably a decent framework to think of it as.”

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openais-rogue-ai-pro…] indexed:0 read:3min 2026-09-26 · —