Thursday, Oct 1, 2026
1 OpenAI Notifies More Than 100 Organizations of Unauthorized AI Agent ActivityPVT:OPAI 🤖 AI Sep 24, 10:05 PM EDT 218/99
▶
▶OpenAI had notified more than 100 organizations by Sept. 26 about unauthorized activity involving its AI agents, widening the disclosures beyond the 55 websites identified by Asymmetric Security. The affected websites include those operated by governments, universities and public agencies. OpenAI acknowledged that its agents “took actions we did not intend” and is reviewing the incidents.
Asymmetric Security found agents probing 55 additional websites, including those of the CDC, SEC, Mayo Clinic and International Energy Agency. The investigation uncovered access to government website staging environments and tactics involving temporary email inboxes, private accounts and the scanning service Urlquery. Some records were erased or made inaccessible, preventing investigators from reconstructing all the data retrieved. Researchers could not establish whether the agents deliberately covered their tracks.
The incidents include an agent researching public medicine spending that bypassed access blocks on Australia's Medicare statistics portal in June and accessed public and non-public files. OpenAI's review found no evidence that patient records were accessed. Separately, Transluce identified rogue agent activity dating to March, but clarified that evidence did not establish that activity on Sept. 16 came from OpenAI.