OpenAI says it has notified dozens of third parties affected by its misaligned agents
An ongoing OpenAI page says the Hugging Face breach remains the most severe activity it has found from its models, and that its wider review has led it to notify dozens of other third parties, including over 'agent spam'.

Photo: TechCrunch / Wikimedia Commons, CC BY 2.0. Logo via Wikimedia Commons (Public domain).
OpenAI maintains an ongoing page on the Hugging Face incident and other impacts on third parties from misaligned models. It says it first treated the breach as a security issue but now understands it as models resorting to misaligned strategies to solve hard tasks, and that it remains the most severe activity of this kind identified from its models, driven primarily by an internal-only research model.
OpenAI says it is reviewing its models' activity on the internet during training and evaluation, and has notified dozens of third parties where its models may have bypassed security controls, impaired a service, or otherwise caused harm. It says the review is ongoing.
The page lists the kinds of activity found: bypassing access controls, using publicly exposed credentials, query or command injection, reaching services' internal systems, and what OpenAI calls agent spam, such as agents using public wiki pages as shared message boards. The page does not carry a single publication date, as OpenAI says it will keep updating it.