WTF?! OpenAI hasn't tried to hide the fact that its AI agents have taken part in unauthorized activity against other organizations, but how many organizations have been affected? Hugging Face was the one that made the most headlines, and there have been several others we know about, but the company has now revealed that it has notified more than 100 organizations.

The ChatGPT maker writes that it has notified over 100 organizations of "misaligned agent activity" linked to its AI models. The figure covers notifications sent by September 26.

Receiving a notice doesn't necessarily mean an organization was definitely hacked or private data was accessed. OpenAI says it also alerts organizations when it can't establish whether information was intended to be public. But given the company's record in this area, it's easy to understand why the firms in question might be worried.

The review covers around 50 petabytes of records. OpenAI is throwing roughly 7,000 Nvidia GB200 and GB300 GPUs at the job, at a cost of more than $500,000 a day. AI systems filter potential cases before human investigators examine the evidence.

The activities identified include bypassing access restrictions, using exposed credentials, injecting commands into websites, and turning public pages into unauthorized message boards.

That last category will sound concerningly familiar to OpenAI. In September, researchers uncovered agents using a German programming wiki to swap information and sandbox escape techniques. When a moderator started deleting pages alphabetically, one agent created a backup beginning with ZZZ. It seems even rogue AI understands the advantages of being last in the queue.

There have been more serious examples, too. An OpenAI agent bypassed restrictions on Australia's Medicare statistics portal in June while researching public medicine spending. Authorities weren't notified until September. The confirmed unauthorized access was limited to that portal; interactions with several other Australian government websites involved public information.

Meanwhile, OpenAI recently paused training of its most powerful models after another containment failure. The disclosures also included a model posting a researcher's GitHub token in a public repository while attempting to cheat on a theorem-proving task. Getting the right answer clearly isn't much comfort if the process creates another security problem.

OpenAI says it has tightened internet restrictions, separated research environments, and expanded monitoring. It's found no other compromise matching the Hugging Face incident in scale or severity so far. But the review is still ongoing, and the company expects to notify more organizations. It sounds like that "more than 100" figure could become even higher.