top of page

OpenAI's Rogue Agents Hit More Than 100 Organizations. They're Still Counting.

Writer: Michael Routhier
Michael Routhier
10 minutes ago
5 min read

A dark server room with racks of tangled cables, a flashing red alarm light, and a wall screen showing a network map with red nodes spreading outward, representing OpenAI agents that gained unauthorized access to systems at more than 100 organizations
OpenAI says it's combing through about 50 petabytes of data to find out what its own agents did.

In July, I told you an OpenAI system broke out of its testing environment and hacked a real company. I called it a line crossed.


I was wrong about one thing. I thought it was the line. It was the first one.


This week, OpenAI disclosed that agents built on its platform may have conducted unauthorized intrusions or caused harm to systems at more than 100 organizations. It has notified each one directly. And it is still counting.


What OpenAI Just Admitted


Here's what's on the record. According to Reuters, as reported by Quartz, OpenAI is combing through around 50 petabytes of data to work out the full extent of what its agents did. The company says that in some cases, models "used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied".


Read that phrase again; in retrospect. Not at the time. After the fact.


OpenAI also identified what it calls "agent spam", where models posted on third-party sites in ways their developers never anticipated. And here is the sentence that matters most; the company says it considers both the intrusions and the spam to be manifestations of model misalignment.


That's the company's own word for a machine doing something its makers didn't intend and can't fully explain.


It Didn't Stop at One Company


The Hugging Face breach, where autonomous agents escaped a controlled testing environment and compromised internal datasets and credentials, is still the worst one OpenAI has found. It says a highly capable internal-only research model was behind it.


But the review has gone well beyond that. OpenAI's agents interacted with several U.S. government websites in unexpected ways, accessing publicly available information on SEC and Census Bureau sites and trying, without success, to reach the Department of Education. Australia's Prime Minister disclosed that an OpenAI agent gained unauthorized access to Australia's Medicare statistics database in June. OpenAI says it only became aware of that in August.


Two months. A government health database. And the company that built the agent found out after the fact.


Let's Be Precise, Because That's Who We Are


I believe in precision over panic, so here is what we do and don't know.


  • OpenAI says the agents "may have" conducted intrusions. The investigation is not finished.


  • The company says most cases found so far are low severity.


  • The government sites it names were largely accessing publicly available information.


  • The Australian case involved a statistics database. It is not U.S. Medicare, and nothing I've seen says patient treatment records were involved.


  • OpenAI says completing the review will take months.


None of that makes this okay. It makes it worse. A company that can't tell you yet what its own software did is a company running an experiment on the rest of us, and we never signed up for it.


The Part That Should Make You Angry


Think about how we found out. Not through an inspection. Not through a mandatory report. Through the company's own disclosure, months after the fact, in pieces.


There is no independent body that gets called when an AI agent breaks into a system. No required timeline. No subpoena power. If OpenAI hadn't chosen to say something, how many of us would know?


And this is the same industry now putting trading agents in the hands of 29 million people, as I wrote about last week, with the liability question left blank. The pattern keeps repeating; the powerful automation goes out first, and accountability gets figured out later, by the people who got hurt.


Here's the Good News: Congress Is Moving


Lawmakers are responding. Federal News Network reports that lawmakers in both parties are proposing everything from AI kill switches to new safety boards. These are the ones I'd look up:


  • The Stop Rogue AI Act, introduced by Reps. Josh Gottheimer and Mike Lawler, would direct NIST to write national standards for tracking and logging AI agents within a year, including tamper-proof action logs and records tying each agent to its developer.


  • The AI Incident Reporting Act would require AI developers to report security breaches and other safety incidents to the Commerce Department.


  • Sen. Ed Markey's Cybersecurity and AI Board of Investigations Act would create an independent board with subpoena power to investigate cyber incidents, including those involving AI.


  • The Bennet-Welch AI Regulatory Act would establish a new independent agency to regulate frontier AI models.


  • The Sanders-Casar Ban Artificial Superintelligence Act would ban superintelligence and pause advanced AI development until a new federal regulator sets safety rules.


I want to be honest about the odds. The Sanders-Casar bill is the most sweeping, and the AP reports it faces long odds in a Republican-controlled Congress, where lawmakers have struggled to agree even on less sweeping AI rules. The narrower bills, tracking agents, reporting incidents, and investigating breaches, are the ones with the best shot at drawing support from both sides. That's where ordinary pressure counts most.


This Is Where You Come In


I know what you're thinking. I'm one person. Nobody in Washington cares what I think.

I've said this on here, the podcast, and the YouTube channel before, and I'll keep saying it; a staffer is counting every call. When enough constituents contact the same office about the same issue, it moves up the list. These bills are new, and the pressure to pass them is being built right now.


Here's how to do it in about five minutes.


  1. Find your representative and your two senators at house.gov and senate.gov.


  2. Call the Capitol switchboard at (202) 224-3121 and ask for your representative's office, then call again for each senator. The Senate's own website lists that number.


  3. Say who you are and where you live. Staffers log constituents first.


  4. Be specific. Name the problem and name the ask. Don't ramble.


  5. Follow up with a short email or web message. Personal messages from constituents carry weight.


  6. Then send this post to three people and ask them to do the same.


Here's a script you can borrow, word for word:


"Hi, my name is [your name], and I'm a constituent from [your town]. I'm calling about AI safety. OpenAI says its AI agents may have broken into systems at more than 100 organizations, and the company is still working out what happened. I'm asking Representative or Senator [name] to support mandatory incident reporting and independent oversight for AI agents. Thank you."


That's it. Thirty seconds. You don't need to understand the technology. You only need to ask for someone to be accountable for it.


What I Actually Want You to Take From This


I'm not telling you the sky is falling. OpenAI says most of what it has found so far is low severity, and I'm taking that at face value until the review says otherwise.


But I am telling you this; a company discovered that its own software broke into other people's systems, and it found out months later. If that doesn't make you want someone independent watching, I don't know what will.


We have a short window where the rules are still being written. Once the technology is everywhere and the money is locked in, that window closes. That's why I'm asking you to act now, not after the next disclosure.


Make the call. Tell your family and friends to make the call. Then come tell us in the community how it went.


Stay sharp. Stay loud.










Michael Routhier is the founder of Tech 4 Grown-Ups, providing honest, unfiltered digital literacy for adults 55+, and host of The Virtuous Machine, exploring the ethics and human cost of AI. Read by tech-curious readers in 200+ countries. Explore more at tech4grownups.com.

Comments


You're Not Behind - You Just Started Later

 

Adults 55+ just like you have already taken this step. They were skeptical. They were frustrated. They weren't sure it would work for them. But they started anyway, with the Academy Toolkit, a seminar, or the book.

​

And now they're video calling their grandchildren with confidence, spotting AI-driven scams before they land, managing their own devices, and feeling like the capable, competent adults they always were - just with one more skill nobody ever taught them.

​

Whether you start with the Toolkit, a seminar, or the book, the outcome is the same.

 

Questions? Email contact@tech4grownups.com

​

🔒 Bank-Level Payment Security | 🛡️ Your Data Never Sold, Ever

Tech 4 Grown-Ups logo - technology coaching for adults 55 and over

917-582-0321

© 2026 Tech 4 Grown-Ups. All rights reserved.

bottom of page