
OpenAI CEO Sam Altman speaks during an event in San Francisco, Calif., on June 2, 2025. Justin Sullivan/Getty Images
OpenAI said it has alerted global institutions that their websites may have been meddled with by artificial intelligence agents it is developing.
“Some of the websites involved are operated by governments, universities, public agencies, and other institutions,” the creator of ChatGPT said on Friday as part of an ongoing review of how its advanced AI models behaved while accessing the internet during internal training and testing.
OpenAI said some of its models bypassed access controls, used exposed login credentials, or interacted with websites in ways that affected outside systems.
There were also incidents of “agent spam,” in which AI agents posted content to third-party websites without being instructed to do so. In one example, agents used public wikis as makeshift message boards to exchange information with one another.
The company said that it has notified “dozens” of affected organizations so far and that the review remains ongoing. OpenAI said it will continue contacting third parties as additional cases are verified.
In addition, OpenAI said it has so far identified 53 cases in which agents uploaded user-provided images to external image-hosting sites as unlisted links. Most of them have already been removed in cooperation with the hosting providers, while some remain online.
OpenAI has not disclosed whether those images depicted real people or were AI-generated, or when they were uploaded.
The broader investigation follows a more serious incident involving Hugging Face, an online platform widely used by AI developers.
OpenAI disclosed in July that a group, or “swarm,” of its AI agents had broken out of restrictions within a testing environment and compromised Hugging Face systems without explicit instruction.
“As agents used more reasoning effort, some pursued increasingly risky and out-of-bounds strategies, including eventually exploiting third-party infrastructure,” it stated in an Aug. 26 report into the Hugging Face incident.
OpenAI now said it has since strengthened restrictions on how research models can access external systems, while reviewing older training and evaluation activity for previously unidentified incidents.
CEO Sam Altman acknowledged Friday that the review has taken longer than the company would have preferred.
“We have not been as fast as we would have liked,” Altman wrote on X, saying OpenAI is trying to balance transparency with the need to understand “petabytes of agent activity logs” and coordinate with affected organizations.
“Hugging Face is still the most severe event we’ve seen,” he said.
Hugging Face was the first to publicly disclose the incident. OpenAI later acknowledged responsibility for the breach.
Clément Delangue, CEO of Hugging Face, raised concerns about transparency during Wednesday’s United Nations Security Council session on AI.
“I often wonder what would have happened had we decided not to disclose this attack publicly,” Delangue said, adding that similar incidents had occurred earlier at a “handful of frontier labs” without public monitoring.









