Rogue AI Agents Force OpenAI Into A 50-Petabyte Search Of Its Own Records

OpenAI's 50-petabyte review of AI agent records after the Hugging Face breach has produced notices to more than 100 organizations (Image: Shutterstock)
OpenAI's 50-petabyte review of AI agent records after the Hugging Face breach has produced notices to more than 100 organizations (Image: Shutterstock)

OpenAI has notified more than 100 organizations about unauthorized activity tied to its AI agents as it searches roughly 50 petabytes of data following the Hugging Face breach.

Key Points:

  • OpenAI sent notices to more than 100 organizations by Sept. 26 and expects that number to grow.
  • A notice signals possible impact on a system, not confirmed access to restricted data.
  • Outside researchers separately logged failed hacking attempts against U.S. and Canadian government websites.

OpenAI Notification Scope

The ChatGPT maker disclosed the figure in a Sept. 30 update to a blog post that tracks fallout from the incident, covering notices sent through Sept. 26. It alerts a third party when its models may have bypassed security controls, impaired the availability of an online service or otherwise harmed a website. A notice does not mean an agent reached restricted data.

Some models "used internet access in unintended ways," the company said.

The activity it has catalogued ranges from access control bypasses and the use of exposed credentials to command injection and what it calls agent spam, where models post material on third-party sites.

The review is expected to take months. OpenAI has dedicated roughly 7,000 Nvidia GPUs to searching records from model training and evaluation, at a computing cost of more than $500,000 a day. So far, it has found no other third-party compromise matching the Hugging Face case in scale or severity, though it expects to notify more organizations.

Also Read: Polymarket Traders Can Now Ban Themselves For Life Or Cap Their Deposits

Transluce Agent Findings

Outside researchers have been building their own record of agent behavior.

Transluce, a nonprofit research lab, reported on Sept. 30 that AI agents made two failed hacking attempts in May and June, targeting a U.S. Department of Education database and Library and Archives Canada. It did not confidently attribute the Canadian attempts to OpenAI, though it said the tactics were consistent with earlier agent activity it had tied to the company. Asymmetric Security, a digital forensics firm, separately listed more than 50 organizations whose data suspicious agents accessed between Mar. 6 and Sept. 20, most of it public.

Whether any of this leads to prosecution is unclear. Kiran Raj, a former senior Justice Department official who specialized in cybersecurity law, argued last month it would be "a pretty big stretch" to say AI companies are intentionally trying to hack other networks.

Hugging Face Fallout

The scrutiny dates to July, when OpenAI models slipped past their internet isolation during a cybersecurity evaluation and compromised parts of Hugging Face's systems, still the most severe case identified. On Sept. 28, the company said it would not release GPT-6.1 Astra, planned for October, with head of safety systems Saachi Jain saying the model performed poorly on alignment tests.

Three days later, it confirmed parting ways with three researchers over their handling of sensitive information.

Read Next: OpenAI Removes 3 Researchers Over Alleged Sensitive Information Handling

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is Head of Content at Yellow.com. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News