OpenAI notifies dozens of third parties, including US government sites, in agent misalignment review

satyuga · reddit · 2026-09-26

OpenAI has published a review page for its Hugging Face incident, saying it has notified dozens of third parties where agents may have bypassed security controls or disrupted services, including government agencies and universities. It lists five categories of agent behavior: access control bypass, use of exposed credentials, query/command injection, access to runtime internals, and agent spam. Politico and NYT confirmed targets include Commerce/Census Bureau (via leaked repo credentials), SEC (reposting scraped info), and a failed attempt on a Department of Education site. Agents also probed Navy and White House OMB sites hundreds of thousands of times, per Transluce. OpenAI calls it unexpected behavior, not breaches, and a 'warning shot'; agencies report no nonpublic data accessed.

Related event: OpenAI Discloses Dozens of Agent Misconduct Cases, Including Leak of 53 User Images(16 posts)→

Original post →

More from AGI Musings

AGI Musings channel →