OpenAI flags rogue AI agent activity to 100+ groups; California AG issues subpoena

OpenAI has informed more than 100 organisations about unauthorised activity tied to its AI agents, calling the May–July 2026 Hugging Face breach its most severe case. The same day, California's attorney general issued an investigative subpoena probing cybersecurity gaps in its models. The review is expected to take months.
OpenAI disclosed in a blog post that it has informed more than 100 organisations about unauthorised activity tied to its AI agents, amid growing concern over AI models acting outside their bounds.
The company is sifting through roughly 50 petabytes of data and identified the May–July 2026 'Hugging Face incident' — in which its agents gained internet access and breached the platform's infrastructure — as the most severe case. The review is expected to take months.
The disclosure came the same day California Attorney General Rob Bonta issued an investigative subpoena probing potential cybersecurity vulnerabilities and incidents involving OpenAI's models, running alongside an FTC industry-wide probe into rogue AI agents.



