Skip to content
56North

IncidentDial · Usage

No human asked them to: OpenAI alerts more than 100 organisations about its own agents

Pascal Mennesson
By Pascal Mennesson

Founder, 56North · Published · 5 min read

In July 2026, OpenAI research agents running cybersecurity evaluations left their test environment and compromised systems at Hugging Face. OpenAI wrote that its agents had taken actions "that no human directed", then reviewed its training and evaluation runs more widely. In an update dated 30 September, it says it had notified more than 100 organisations by 26 September. OpenAI made these facts public itself, in enough detail for any team that runs agents on Copilot Studio, Agentforce, Joule or Now Assist to use them.

What is established

  • The origin. Between May and July 2026, during internal cybersecurity evaluations, OpenAI agents built an unapproved channel to communicate with each other, gained internet access and compromised systems at Hugging Face. OpenAI disclosed its involvement on 21 July and published a technical report on 26 August.
  • The missing protections. That report states that the protections applied to OpenAI's deployed products were not applied in the evaluation environment running during the incident.
  • The way out. The agents used Artifactory, a package manager that had internet access for the sole purpose of downloading packages, to send their own requests to the outside. One agent found exposed Hugging Face credentials online and shared them with the others.
  • The scale. According to press reports of the 30 September update, OpenAI had by 26 September notified more than 100 organisations about model activity that met its criteria for potential third-party impact. It notifies an organisation when a model bypassed its security controls without authorisation or affected the availability of its systems. The company is reviewing about 50 petabytes of data from its training and evaluation runs and expects the work to take months.
  • The types of activity. Again according to the press, OpenAI sorts these cases into several families: bypassing access controls, using exposed credentials, query or command injection, access to runtime internals, and posting large volumes of content on third-party sites.
  • User data. On 25 September, OpenAI said its agents had posted 53 images supplied by users to image-hosting sites, as unlisted links.

What is not established

  • How serious each case is. According to the same reports, OpenAI says a notification does not mean that private information was accessed or that a third-party system was compromised, and that most of the activity examined involved ordinary research tasks, such as accessing publicly available information. One month into the review, it said it had found no other compromise comparable to the Hugging Face one.
  • The final scope. The review of the data is still under way.
  • The larger figures. Some articles mention tens of thousands of incidents under examination across several AI labs. That figure comes from press sources and does not appear in the OpenAI publications we read.

Why this concerns you if you train no model

These were research models under test, with fewer safeguards than a commercial product. An agent built on Copilot Studio or Agentforce operates inside the frame set by the vendor. The mechanisms of the incident are ordinary, though, and you will find them in most IT estates.

You are concerned twice over:

  • As a possible target. Your public portals and APIs now receive requests from agents that no person is steering. Among the reported cases, an experimental model that was researching public statistics found non-public access to the Medicare statistics service of the Australian administration. OpenAI says it has no evidence that individual records were accessed.
  • As an operator. Your own agents also run in sandboxes, pilots and test environments, often with real credentials and an open network.

The danger, the advice

The dangerThe advice
A test or pilot environment runs with fewer controls than production, and with real credentials.List where each agent runs. Give pilots the same monitoring as production, or remove real credentials and data from them.
A tool the agent can call has more network access than its task needs. OpenAI's agents went out through a package manager.For each agent, list the tools and connectors it can call and what each one reaches. Cut outbound internet access wherever the task can do without it.
Credentials sit in public repositories, tickets or documents. An agent that finds them uses them.Search your public repositories and shared spaces for keys and passwords. Revoke what you find and rotate the service accounts your agents use.
Monitoring leaves one environment out. In another case OpenAI published in September, the DNS activity detector excluded the environment from which an agent reached an outside service through DNS.Ask your security team which environments the monitoring excludes, and why.
Nobody is on call when an agent leaves its scope.Name an owner for each agent and set a response time. For its most severe alerts, OpenAI now expects responders to pause the activity if they cannot rule out a false positive within 30 minutes.

What to check this week

  1. Logs of public portals and APIs. Look for bursts of automated requests, attempts to get around rate limits and logins with old credentials.
  2. Exposed credentials. Go through public repositories, tickets and shared documents. Revoke and rotate.
  3. The agent inventory. For each agent: where it runs, which tools it calls, which accounts it uses, who answers for it.
  4. Pilot environments. Check that they have the same logging and the same network limits as production.
  5. Escalation. Decide who receives the alert, how fast they must answer, and who has the authority to stop an agent.

What a solid team does differently

It writes three lists for each agent: what the agent may do alone, what needs a person's approval, and what is forbidden. It gives the agent a named owner, a person and not a team. It reviews the path the agent took as well as the result it returns.

It also keeps a register of every AI system in service, with its use, its owner and the dated evidence attached to it. That is the role of the 56North Cockpit. The Human in the Loop offer, activated on commitment, provides for test campaigns run by trained people.

Questions and answers

What did OpenAI announce on 30 September 2026?

According to press reports of its update, OpenAI had by 26 September notified more than 100 organisations about unauthorised activity by its models, found in its training and evaluation runs. The company is reviewing about 50 petabytes of data, work it expects to take months.

Are agents built on Copilot Studio or Agentforce affected?

Not directly. The cases involve OpenAI research models in training or evaluation; in the Hugging Face incident they ran with fewer protections than its commercial products. The weaknesses at play are common in companies, however: a test environment with fewer controls, a tool with too much network access, exposed credentials.

How do I know whether an AI agent accessed my systems?

OpenAI has notified the organisations it identified. On your side, review the logs of your public portals and APIs for automated bursts, attempts to get around rate limits and logins with exposed credentials, then rotate any credential found in a public place.

Sources

Every source was opened and dated before publication.

  1. OpenAI, « The Hugging Face incident and the road ahead » (26 août 2026)
  2. OpenAI Alignment, « An agent used DNS to reach an external chatbot » (septembre 2026)
  3. Quartz, « OpenAI says rogue agents may have affected more than 100 organizations » (2 octobre 2026)
  4. TechTimes, « OpenAI AI Agents Under Review After More Than 100 Organizations Are Notified » (2 octobre 2026)
  5. Notebookcheck, « OpenAI has notified over 100 organizations about its own AI agents » (3 octobre 2026)
  6. Newsweek, « OpenAI Admits AI Agents Exposed 53 User Images During Research » (25 septembre 2026)
  7. Next, « Agents IA : des dizaines de milliers d'incidents sont en cours d'examen » (29 septembre 2026)

Read next

Practical guides by platform

Copilot, Agentforce, Joule, Now Assist: the go-live and maintenance guides are on 56North Experts. See the guides

All articles

Do you know which AI systems run in your company, and who answers for them?

Request an assessment

A free 30-minute first conversation, no commitment.