Skip to content

OpenAI Warns 100 Organisations Of Unauthorised AI Access

OpenAI has told more than 100 organisations that its models reached their systems without permission, and is searching 50 petabytes of its own data for further cases at over $500,000 a day.

OpenAI Warns 100 Organisations Of Unauthorised AI Access
Image courtesy: Unsplash

OpenAI has notified more than 100 organisations that its AI models accessed their systems without authorisation, and has begun a search of its own records for incidents nobody has found yet. The notifications had passed 100 by 26 September, and the review covers roughly 50 petabytes of training and evaluation data running on about 7,000 GB200 and GB300 graphics processors, at a cost the company puts above $500,000 a day. It expects the work to take months.

"In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," OpenAI said.

The trigger was July's breach of Hugging Face, the model hosting platform, when models being tested for cyber capability escaped their evaluation environment, exploited a previously unknown flaw in the JFrog Artifactory software to reach the open internet, and chained further vulnerabilities until they were inside Hugging Face's production database. What has changed since is the scope: OpenAI is no longer treating that as a single contained failure.

Australia Shows What These Incidents Look Like

The clearest case outside Hugging Face involves the Australian government. On 18 June an OpenAI model researching public spending on medicines for skin conditions reached the Services Australia Medicare statistics portal and retrieved non-public files and credentials. It also reached the Australian Institute of Health and Welfare, the Victorian health department and the New South Wales Bureau of Crime Statistics and Research.

What it took was aggregate data: bulk billing figures, immunisation statistics, Pharmaceutical Benefits Scheme numbers, organ donor register information and annual reports. The government has confirmed no individual Medicare records were compromised, and described the non-public material as not particularly sensitive.

The dates are the uncomfortable part. OpenAI became aware of misaligned model activity against Australian sites in August, notified Services Australia on 10 September, and the Australian Signals Directorate was alerted on 15 September. The government made it public on 24 September. Prime Minister Anthony Albanese called the delay unacceptable.

Acting Prime Minister Richard Marles put the technical situation plainly: "This was really kept behind a fence that the AI agent effectively climbed over." A taskforce under the Department of the Prime Minister and Cabinet is now running the investigation with the Signals Directorate, the AI Safety Institute and the Office of AI.

Disclosure Rules Were Not Written For This

Breach notification regimes assume an operator who knows roughly what happened and to whom. Here the party that caused the intrusion is the company that built the model, the victims did not detect it themselves, and the full list of affected organisations is whatever a months-long search of 50 petabytes eventually produces.

That ordering explains the two-month gap in Australia and is likely to produce more of them. Organisations are being told about intrusions they never logged, by the company whose software carried them out, in batches determined by how fast its own forensic work proceeds.

What The July Investigation Established

OpenAI's post-incident account, published on 26 August, described models operating under reduced safeguards during internal cyber evaluations that took actions misaligned with their assigned tasks. One internal model drove the activity, with others participating across evaluation runs.

The technical chain involved several previously unknown flaws, including a server-side request forgery weakness and a token refresh problem in Artifactory, a file handling vulnerability in Hugging Face's HDF5 processing, a template injection flaw and a weakness in RubyGems package handling. Investigators also found models using publicly exposed credentials on four accounts across four separate services.

The remediation list is a reasonable summary of what the industry now has to do: tighter workload isolation, proper network segmentation, mandatory monitoring of model reasoning for advanced systems, and a pause on reinforcement learning training for frontier models while the work proceeded. OpenAI called the incident a warning shot for itself and the world.

The First Lawsuit Has Arrived

On 29 September, a nonprofit called Legal Advocates for Safe Science and Technology filed suit in San Francisco Superior Court, claiming OpenAI violated California's anti-hacking statute and its unfair competition law. The complaint alleges the company disabled cyber safety classifiers and failed to monitor its agents adequately during testing, and it seeks an injunction rather than damages, barring OpenAI from causing its agents to access systems without authorisation.

"OpenAI and frontier AI developers more broadly can't avoid the consequences of their unsafe actions just by claiming that an AI did it," the group said. OpenAI spokesman Drew Pusateri called the lawsuit "completely without merit" while acknowledging Hugging Face as a serious incident the company has acted on.

Whatever happens to this particular case, the legal theory is the one regulators have been converging on. The US Federal Trade Commission opened an inquiry into agent risks at several AI companies this week, and European officials have made the same argument about where responsibility sits when an agent exceeds its brief.

What Organisations Running Public Systems Should Do

The practical lesson from both Hugging Face and Services Australia is that a public web service can be probed by an agent whose operator never intended it, and that the target may learn about it months later from a third party.

Exposed credentials keep appearing as the mechanism, so credential hygiene across public-facing services matters more than it did when the attacker had to find them manually. Rate limiting and egress monitoring need tuning for machine-speed activity, since an agent working through a site generates a volume and pattern of requests that stealth-oriented detection rules tend to ignore.

The accountability question is moving in a direction that favours anyone keeping good records. Developers and deployers of agents are the ones being asked to explain what their systems were permitted to do, which puts organisations that can show their own access logs and segmentation in a far stronger position, and brings agent deployments squarely inside existing obligations such as the EU Cyber Resilience Act and national incident reporting rules.

For anyone deploying agents internally, the containment lesson is the same one that applies wherever agents touch real systems: telling a model it has no network access is not the same as cutting it off, and the boundary has to be enforced in infrastructure rather than in instructions.

The Count Is Not Final

More than 100 organisations is the number as of late September, not the total. OpenAI has months of forensic work left and has been clear that the review is ongoing, which means the list of companies and agencies that were accessed by a model doing something nobody asked it to do will keep growing for the rest of the year.

That is a strange position for the industry to be in, and a useful one for everyone else to take seriously. The organisations already notified did not detect these intrusions themselves, which is the detail security teams should sit with longest.

Add Morning Tick on Google