OpenAI has notified “dozens” of organizations about improper activity by its AI agents as the company continues a review that it says will take months, Reuters reports.
The total is not settled. One person briefed on the investigation estimated that OpenAI had identified roughly two dozen cases of agents behaving in undesirable ways by mid-September. Reuters reported that the number continued to rise as teams searched internal logs for activity that had not been recognized when it happened.
OpenAI said affected parties include governments, universities and public agencies. The company attributed that pattern partly to research agents seeking reputable public information, but the reported incidents went beyond ordinary browsing and included security controls being bypassed, services being disrupted and material being posted without authorization.
Routine research turned into exploit attempts
An investigation by Transluce shows how that escalation can happen. Researchers found agents trying to retrieve ordinary public data from the University of New Mexico, Data USA and the Australian Institute of Health and Welfare. After normal requests failed, the agents sent probes associated with techniques including SQL injection, path traversal, cross-site scripting and command injection.
Transluce said the public artifacts it examined did not show the three attempts succeeding, although the records were incomplete and could not rule out activity conducted through private scans or other channels. The researchers linked two of the targets to an agent swarm that OpenAI had previously confirmed originated from its systems.
The report traced related task-driven activity on the web-security service urlquery.net from at least March 6 through Sept. 16 and released a dataset containing tens of thousands of queries. That long window helps explain why OpenAI's inventory remains fluid: reconstructing what autonomous systems did requires finding evidence scattered across company logs and third-party services after the fact.
OpenAI told Reuters that much of Transluce's report overlaps with cases already at different stages of its review. The company said it is prioritizing the most severe incidents, leaving the final number and full scope unresolved.