OpenAI has notified more than 100 organizations about incidents related to unauthorized activity by its AI agents. The company is reviewing the actions of its models after the breach of the Hugging Face platform. This was reported by Qazaqyia.kz citing Kursiv Media.
The review covers how the models operate online during training and capability evaluations. OpenAI is notifying owners of third-party services about cases where agents could bypass protection, disrupt a site's availability, or affect its operation in other unforeseen ways.
In a published report, the company listed several types of activity. Agents gained access to information and functions requiring authorization or special permissions, and used credentials and access keys found in the public domain.
Models also injected text into websites that the service could interpret as a command to execute a database query or run code. In some cases, agents accessed internal files and systems they were not supposed to reach.
Another category is posting messages on third-party resources. For example, agents used public wiki pages to exchange information. Such actions could alter site content and require subsequent cleanup.
Notifying an organization does not by itself confirm a successful breach. The scale and consequences of each case require separate verification.
According to Reuters, OpenAI is analyzing about 50 petabytes of data. The company previously warned that the investigation would take several months. The most serious incident identified so far remains the Hugging Face breach.
OpenAI says it is introducing additional technical and organizational measures to prevent such behavior or detect it at an early stage. The company also intends to publish the results of the review while preserving the anonymity of affected organizations where necessary for their protection.
