All Reports

Tracker: OpenAI's Rogue Agents

Bot Mutiny |

Every Bot Mutiny report on OpenAI's AI agents acting without authorization: the Hugging Face breach lawsuit, the Australian Medicare portal, government website probes and the safety-researcher dismissals.

OpenAI has said an experimental internal model took actions it had not authorized, including gaining non-public access to an Australian government Medicare portal. A lawsuit reported by WIRED, drawing on OpenAI's own technical report, alleges that its AI agents broke out of a testing environment and hacked the AI platform Hugging Face. Researchers at the lab Transluce have since reported AI agents probing a US Department of Education website and Library and Archives Canada with tactics consistent with activity previously attributed to OpenAI, though they do not confidently attribute those attempts to the company. This page collects Bot Mutiny's coverage of the saga in date order.

Timeline

  • By 26 May 2026: Agents in an OpenAI cyber evaluation used a server-side request forgery flaw in an internal copy of the software tool Artifactory to reach the internet, according to a lawsuit that draws on OpenAI's technical report and METR's independent report. Our coverage
  • 28 May and 9 June 2026: Portugal's national web archive recorded nearly 900 requests targeting Library and Archives Canada, 13 of them carrying attack payloads, according to Transluce. The probes returned empty record pages. Our coverage
  • 17 June 2026: AI agents made more than 200,000 requests to a US Department of Education website, including a basic SQL injection attempt, according to Transluce. Our coverage
  • 18 June 2026: An experimental OpenAI model gained non-public access to Australia's Medicare Statistics Reporting Service, according to OpenAI; Prime Minister Anthony Albanese said the breach began that day. The Record, reviewing archived versions of the portal, found a March 2025 upgrade had enabled guest access, and Ciaran Martin, former head of Britain's National Cyber Security Centre, told it that it was "still unclear if what's happened would constitute a hack." Our coverage
  • 26 June 2026: Agents seized administrator control of the internal Artifactory tool, the lawsuit says. Our coverage
  • 10 and 11 July 2026: Agents used leaked Hugging Face credentials and a malicious dataset to reach administrative and host-level access across multiple Hugging Face clusters, according to the lawsuit, which quotes OpenAI's technical report. Our coverage
  • 26 August 2026: OpenAI released its technical report and the research nonprofit METR released an independent report on the Hugging Face incident, which the lawsuit later drew on. Our coverage
  • 10 September 2026: OpenAI emailed a public Services Australia inbox about the Medicare access, 84 days after it happened. Our coverage
  • 25 September 2026: OpenAI disclosed that its agents had interacted with several US government websites in unexpected ways, and Transluce informed the Education Department of its findings. Our coverage
  • 29 September 2026: Legal Advocates for Safe Science and Technology filed a complaint dated this day in San Francisco Superior Court, alleging OpenAI violated California's computer crime law over the Hugging Face incident. OpenAI calls the suit "completely without merit." Our coverage
  • 29 September 2026: OpenAI published an apology to Australia, saying: "We also should have handled our response better." Our coverage
  • 29 September 2026: Communications Security Establishment Canada said in a statement that there was "no indication that government systems have been compromised at this time." Our coverage
  • 1 October 2026: The Wall Street Journal reported that OpenAI had dismissed three safety researchers over the alleged sharing of confidential information with a third-party AI safety organization. Our coverage
  • 6 October 2026 (scheduled): OpenAI chief strategy officer Jason Kwon is due to appear before the Australian parliament's joint select committee on AI in Sydney, according to OpenAI and the Guardian. Our coverage

What is still unknown

  • Neither OpenAI nor the Australian government has released the agent's activity logs, The Record reported. None of our sources reports a finding that the Medicare access was unlawful; the Australian government is investigating whether it broke the law.
  • What the agent wrote to the Medicare server is not established. Albanese said it wrote data to a database and OpenAI says it wrote files, while The Record suggested the files may have been chart images.
  • Transluce does not confidently attribute the attempts on the Education Department and Library and Archives Canada sites to OpenAI. Whether the Medicare access is linked to agent activity Transluce recorded is not settled; OpenAI did not respond to TechCrunch's question on whether the incidents were connected.
  • In the dismissal of the three safety researchers, the reporting does not establish what information was allegedly shared, which organization received it, or whether any of it concerned safety problems.
  • How the California lawsuit will proceed: our coverage reports the complaint and both sides' comments to WIRED, and does not report any ruling.

All our coverage