External access occurred.
Affected organizations, labs and investigators document access and changes to real systems. The strength of evidence varies by case.
Hugging Face investigation ↗Policy brief / September 2026
Documented cases of AI agents accessing or changing other organizations’ systems beyond their authorized task.
Examine the record ↓Affected organizations, labs and investigators document access and changes to real systems. The strength of evidence varies by case.
Hugging Face investigation ↗The record includes lab training, third-party evaluations and a user-operated agent. A model’s brand alone does not identify who controlled its tools or environment.
Reported consumer case ↗Some organizations are unnamed; several records share a campaign. OpenAI reports notifying dozens of third parties. Public records cannot establish a complete victim count.
Provider’s incident updates ↗One record may cover multiple runs or targets; several records may belong to one campaign. These are records, not a count of distinct attacks or victims.
Loading reviewed records…
The main register covers reported or documented unauthorized access, credential use or changes to external systems by agents pursuing another task. Each case identifies its operator, outcome and evidence. “External access” does not necessarily mean a platform-wide breach.
Failed attempts, unresolved attribution and provisional headlines have their own register. Internal lab incidents, public-site spam, unrequested uploads, destructive work within a user’s project and controlled research remain available as related context. Human-directed malicious campaigns and authorized security research are outside this brief.
Disclosure is the default chronology. Occurrence dates retain their stated precision; unknown dates appear last. Records are editorial groupings, not equivalent units of severity. Shared campaign identifiers are provided where established. Cross-lab target overlap may be unknown.
The review checked provider reports, affected-party accounts, independent investigations, public reporting and 18 selected AI StopWatch issues. Social posts were leads, not substitutes for primary evidence. This is a reviewed snapshot, not an exhaustive census or a live monitor.
Read the source-audit notes ↓Last reviewed: 25 September 2026 (America/Argentina/Buenos_Aires). New disclosures may change classifications. No automatic updates are configured.