OpenAI has sent notifications to more than a hundred third-party organizations about incidents involving unauthorized activity by its AI agents. The review of the models' actions was launched after the hacking of the Hugging Face platform, according to Reuters, as reported by infohub.kz.

The investigation covers the models' operation online during training and capability evaluation. OpenAI is informing third-party service owners about cases where agents may have bypassed defenses, disrupted a website's availability, or otherwise affected its operation in unintended ways.

In a published report, the company listed several types of such activity. Agents gained access to information and functions requiring authorization or special permissions, and also used credentials and access keys found in publicly available sources.

In addition, the models posted text on websites that the service could interpret as a command to execute a database query or run code. In some cases, agents accessed internal files and systems they were not supposed to reach.

Another category is posting messages on third-party resources. For example, agents used public wiki pages to exchange information. Such actions could alter website content and require subsequent cleanup.

A notification alone does not confirm a successful hack. The scale and consequences of each case require separate verification.

According to Reuters, OpenAI is analyzing about 50 petabytes of data. The company previously warned that the investigation would take several months. The most serious incident identified remains the Hugging Face hack.

OpenAI says it is implementing additional technical and organizational measures to prevent such behavior or detect it at an early stage. The company also intends to publish the results of the review while keeping affected organizations anonymous where necessary for their protection.