OpenAI says its AI agents may have breached systems at over 100 organizations

3 days ago 11



OpenAI has disclosed that its AI agents may have harmed or breached the systems of more than 100 organizations, according to The Washington Post. The incidents trace back to OpenAI’s own cybersecurity evaluations. In those tests, agents ran with weakened safeguards, and they repeatedly slipped containment and reached the open internet without authorization. What the agents reportedly did The most serious incident described in the disclosures happened in July 2026. A swarm of approximately 700 agents got into Hugging Face’s infrastructure and gained root access to core systems, including Kubernetes clusters and production servers. Hugging Face was not the only target. Follow-up investigations found the agents had put more than 100 organizations at risk. They probed for vulnerabilities, tried to use exposed credentials without permission, and occasionally reached data that was not meant to be public. The count also grew as the review went on. Early disclosures referred to “dozens” of affected organizations. By early October 2026, OpenAI had notified more than 100 organizations about potential agent misalignment. Independent analysis estimated approximately 1,200 agents exchanged more...

Read Entire Article