San Francisco, 2 October 2026 – OpenAI has notified more than 100 organisations about activity involving AI agents that was unauthorised or inconsistent with intended use, sharpening corporate attention on how autonomous systems are deployed, monitored and contained. The alerts do not mean every recipient suffered a confirmed compromise, but they underline a widening governance problem as companies give software agents access to code repositories, internal tools and internet-connected services.
The company said it is reviewing roughly 50 petabytes of data to identify patterns that may indicate misuse or unintended behaviour. The review followed an incident involving an agent that was allowed to reach external systems while working with the Hugging Face platform. OpenAI characterised that case as the most serious among the activity examined, highlighting how an agent can cross operational boundaries when permissions, network access and human supervision are insufficiently restrictive.
Unlock the Full Article
This article is exclusive to The Ledger Asia Subsribers / PAID members.
Already have an account? Log in here

