OpenAI Alerts More Than 100 Organisations Over Rogue AI Agent Activity
The company says unauthorised AI-agent activity has affected organisations across sectors, highlighting emerging risks as autonomous systems gain greater access to digital tools.
SAN FRANCISCO, Oct 2: OpenAI has alerted more than 100 organisations about incidents involving unauthorised activity linked to AI agents, highlighting a growing cybersecurity challenge as artificial intelligence systems become increasingly capable of carrying out tasks with limited human intervention.
The company disclosed the alerts after identifying activity in which AI agents were allegedly used in ways that could expose organisations to security risks. The development has drawn attention to a new category of threats in which artificial intelligence is not merely used as a tool by attackers but can itself perform multiple steps of a cyber operation.
OpenAI’s disclosure comes as companies and institutions are rapidly deploying AI agents capable of interacting with software, analysing information, writing code, accessing digital services and completing sequences of tasks. Unlike conventional chatbots, agentic systems can be designed to make decisions and take actions across multiple stages of a workflow.
That added autonomy can improve productivity, but it can also create new security vulnerabilities if an AI system is manipulated, compromised or given excessive permissions.
According to Reuters, OpenAI informed more than 100 organisations about incidents involving unauthorised activity associated with its AI agents. The company has been monitoring the use of its systems for suspicious behaviour and has taken action where it identified misuse.
The warnings come at a time when the technology industry is moving from conversational AI toward systems that can independently execute tasks. Businesses are increasingly experimenting with agents for software development, customer support, research, data analysis and administrative functions.
An AI agent can potentially interact with several applications during a single task. For example, a system might read documents, retrieve information from databases, generate code and communicate with another service. Such capabilities can make agents more useful, but they also mean that a compromised system could potentially have access to several interconnected resources.
Security specialists have therefore been focusing on the question of how much authority AI agents should receive.
Traditional cybersecurity models generally assume that software performs predefined functions under established access controls. Agentic AI introduces a more dynamic environment because the system may determine the sequence of actions required to complete a task.
This creates challenges around identity, authentication, access permissions and monitoring.
One concern is excessive privilege. If an AI agent has access to email accounts, internal databases, cloud storage or software-development systems, an attacker who gains control of the agent could potentially exploit those permissions.
Another issue involves prompt injection and malicious instructions. AI systems can process information from external sources, including websites, documents and messages. If malicious instructions are hidden inside those sources, an AI agent may potentially interpret them as part of the task it is supposed to perform.
The risks become more significant when agents are permitted to take actions automatically rather than simply providing recommendations to human users.
OpenAI’s latest warnings therefore underscore the importance of monitoring AI systems after deployment rather than treating security as a one-time development requirement.
Companies adopting autonomous AI tools may need to maintain detailed logs of agent activity, restrict access to sensitive resources and introduce approval mechanisms for high-risk actions.
Human oversight can also remain important for activities involving financial transactions, confidential information, account permissions or changes to critical infrastructure.
The issue is particularly relevant to software development. AI coding agents are increasingly capable of creating and modifying programmes, reviewing code and interacting with development environments.
While these capabilities can accelerate software engineering, they also create opportunities for malicious actors to exploit automated systems. An AI agent with access to source code and deployment infrastructure could potentially become a high-value target.
The emergence of AI-assisted cyber operations is also changing the nature of threat detection. Security teams traditionally look for known malware, suspicious network activity or unusual login behaviour. AI-driven activity may instead involve legitimate tools being used in unusual combinations.
This means defenders may need to analyse not only what a system accesses but also why it performed a particular sequence of actions.
The development comes against the backdrop of a broader expansion of autonomous AI technology. Companies are investing heavily in systems that can perform multi-step tasks without requiring users to provide instructions at every stage.
OpenAI is among several major technology companies developing agentic AI products. The technology is expected to become increasingly integrated into workplace software and enterprise applications.
However, the growing autonomy of these systems has also prompted discussions about accountability. When an AI agent performs an unauthorised action, responsibility can become more complicated if the action resulted from a combination of user instructions, model behaviour, external data and software permissions.
This makes governance an important part of enterprise AI adoption.
Organisations may increasingly need policies defining which tasks agents can perform independently and which actions require human approval. Access controls can also be designed around individual tasks rather than providing an agent with broad access to an entire system.
Security researchers have also been examining ways to isolate AI agents from sensitive infrastructure. Sandboxing, permission controls and separate execution environments can limit the potential damage if an agent behaves unexpectedly.
Another priority is continuous testing. AI models can behave differently depending on the information they receive, meaning that security testing cannot necessarily be limited to conventional software vulnerabilities.
Companies may need to test agents against malicious instructions, manipulated documents, deceptive websites and attempts to obtain confidential information.
The incidents disclosed by OpenAI demonstrate that AI security is no longer limited to protecting the model itself. Organisations must also consider the wider ecosystem in which AI systems operate.
As AI agents gain access to enterprise applications, cloud platforms and digital identities, their security becomes closely connected to the security of the organisations deploying them.
The warnings also highlight the dual-use nature of autonomous AI. The same ability that allows an agent to automate complex business processes can potentially be misused for harmful activities.
For technology companies, this creates pressure to develop systems that are both capable and resistant to abuse.
The coming years are likely to see greater investment in AI-specific security controls, including agent identity management, activity monitoring, permission boundaries and automated detection of suspicious behaviour.
For businesses, the latest alerts serve as a reminder that adopting AI agents involves more than evaluating productivity gains. Organisations must also assess what systems the technology can access, what actions it can perform and how those actions can be monitored.
As autonomous AI moves deeper into enterprise environments, maintaining control over these systems could become one of the central cybersecurity challenges of the next phase of artificial intelligence.