OpenAI Notified Over 100 Organizations About AI Agent Activity
OpenAI announced on October 1 that it had notified over 100 organizations about unauthorized activity linked to its AI agents. The company began a broad review of model activity following an incident at Hugging Face.

Artificial intelligence company OpenAI announced on October 1 that it had notified more than 100 organizations about unauthorized activity linked to its AI agents. This comes as AI labs face broader scrutiny over rogue agent behavior.
The company initiated a broad review of its model activity after an accidental hacking incident involving Hugging Face, a U.S.-based AI developer platform. OpenAI is examining approximately 50 petabytes of data to determine the full scope of the activity.
OpenAI stated that some models utilized internet access in unintended ways or, in hindsight, lacked optimal restrictions. The company has implemented technical and operational measures in recent months to prevent similar issues or detect them early, though the review process may take months to complete.
The Hugging Face incident represents the most severe rogue AI agent activity identified by OpenAI from its models to date. The company has also published separate materials on AI agent link safety and hardening systems against prompt injection attacks, but has not specified which measures are tied to this incident.