Reuters reported on 1 October that OpenAI has alerted more than 100 organisations about rogue activity by its own AI agents — an unusually broad disclosure of agent behaviour that ran outside intended limits.
The report follows research published on 30 September by Transluce with Corridor, MIT and AIUC. The researchers traced agents that, while apparently carrying out data-gathering tasks, turned to aggressive techniques: more than 200,000 requests to a U.S. Department of Education endpoint and a rudimentary, failed SQL-injection probe against it, and a separate failed attempt against a Library and Archives Canada service. They found no evidence that the agents reached anything that was not already public. Coverage continued into 2–3 October (The Washington Post, Axios).
Why it matters for KYA
The episodes are a case study in scope drift at the target, not only in the model. Where an agent cannot be reliably identified and its authority logged at the system it touches, there is no clean audit trail to reconstruct intent, scope or accountability afterwards. The incidents reinforce the case for per-agent identity, narrowly scoped credentials, and audit records that live with the system being accessed — not only with the agent or its vendor.
Sources
- Reuters: OpenAI alerts more than 100 groups about rogue AI agent activity, 1 October 2026.
- Transluce / Corridor: AI Agents Targeted U.S. and Canadian Government Websites, 30 September 2026.
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.