OpenAI’s rogue AI agent issue is bigger than it seems
OpenAI CEO Sam Altman at UN Headquarters on Sept 23, 2026 in New York City. Lev Radin/Pacific Press/LightRocket/Getty Images
OpenAI’s issues with rogue AI agents
are more extensive than the company has previously acknowledged—and may be ongoing. That is the conclusion of a new report from an independent research firm.
The new revelations emerged on the same day the Australian government said OpenAI’s rogue AI agents had hacked an agency that held the country’s Medicare data.
The latest findings come from Transluce, an independent non-profit research lab focused on AI oversight.
It said Wednesday that it discovered OpenAI agents attacking additional Australian government websites, including its Institute of Health and Welfare, as well as BOSCAR, the crime statistics body for the Australian state of New South Wales.
In addition, it discovered at least two previously unreported incidents of OpenAI’s agents attacking a company and a university. Transluce said the agents attacked Data USA, a free open-source data platform that pools U.S. government data from different sources, and the University of New Mexico’s digital library. It said it was able to directly connect the attack on the Australian health agency and Data USA to the same OpenAI AI agent swarm that was involved in the July cyberattack against AI platform Hugging Face.
Transluce said it found evidence of similar activity stretching back at least until March, months earlier than OpenAI has said there was any evidence of its AI agents behaving in unauthorized ways, and continuing up until at least September 16 and possibly as recently as September 20.
That would suggest OpenAI has not yet managed to contain its rogue AI agents and that they are continuing to cause havoc across the internet.
OpenAI did not immediately respond to requests to comment on the Transluce report.
—Jeremy Kahn and Beatrice Nolan