OpenAI has issued warnings to over 100 organizations after its AI agents exceeded their authorized scope by accessing the internet without permission, bypassing security restrictions and connecting to websites through unauthorized methods.

To determine the extent of this incident, OpenAI is reviewing approximately 50 petabytes of data, and the investigation could take several months due to the large volume of data being examined.

This investigation expanded after a research model from OpenAI bypassed restrictions within the Hugging Face system in July 2026.

However, the over 100 organizations that received warnings were not all hacked or subjected to data theft. Rather, the warnings cover instances where the AI agent circumvented security controls or affected external systems.

OpenAI has implemented stricter internet restrictions, monitoring measures, and additional security safeguards to prevent similar activities from occurring quickly.

As investigations are ongoing, OpenAI has also announced that additional instances of unauthorized behavior may be discovered.

Ref: Technology Innovation