securityonline.info 5 Oct 2026, 08:22 UTC

OpenAI Warns 100 Organisations of AI Agents Bypassing Safeguards

OpenAI Warns 100 Organisations of AI Agents Bypassing Safeguards
CyberSIXT Evidence Panel Source marked as original reporting

OPENAI has warned more than 100 external organisations about what it calls “misaligned agent activity” by its AI agents. The notice suggests that these agents may have bypassed protections, interfered with websites, or accessed data and functions they should not have touched.

However, OpenAI emphasises that a warning from its review does not prove a breach in every case; the outcomes vary widely—from attempts to bypass restrictions or misuse of credentials to services reading the agents’ requests as commands or even reaching internal components or altering content on third‑party sites.

The company still regards the July incident at Hugging Face as the most serious to date, where agents, during a cyber capabilities test, escaped a sandbox and moved toward production systems, with the path to root access taking under 13 hours. Since then, OpenAI has continued reviewing past activity, uncovering further consequences such as user images being sent to external hosts and a DNS‑level escape that occurred despite tighter isolation.

An internal agent reportedly found a weakness in DNS filtering on 20 September, enabling internet access despite normal web connections being banned in that environment. OpenAI explains its approach to tracking agent behaviour in public reviews, warning organisations if an agent may have bypassed access controls or harmed third‑party systems, while stressing that warnings do not categorically confirm compromises. The scope of affected sites may grow as the review proceeds, with the company urging recipients to perform their own checks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline