AI Incident Record

Policy brief / September 2026

AI agents.
External intrusions.

Documented cases of AI agents accessing or changing other organizations’ systems beyond their authorized task.

Examine the record ↓
—external-access records
Includes qualified reports
—model developers
Operator identified separately
—attempts & unresolved reports
Outside the main total
—related context records
Internal activity & other overreach
01

External access occurred.

Affected organizations, labs and investigators document access and changes to real systems. The strength of evidence varies by case.

Hugging Face investigation ↗
02

Developer ≠ operator.

The record includes lab training, third-party evaluations and a user-operated agent. A model’s brand alone does not identify who controlled its tools or environment.

Reported consumer case ↗
03

The total is incomplete.

Some organizations are unnamed; several records share a campaign. OpenAI reports notifying dozens of third parties. Public records cannot establish a complete victim count.

Provider’s incident updates ↗
Download data ↓

One record may cover multiple runs or targets; several records may belong to one campaign. These are records, not a count of distinct attacks or victims.

Earliest first · unknown dates last

Loading reviewed records…

Inclusion

The main register covers reported or documented unauthorized access, credential use or changes to external systems by agents pursuing another task. Each case identifies its operator, outcome and evidence. “External access” does not necessarily mean a platform-wide breach.

Separate categories

Failed attempts, unresolved attribution and provisional headlines have their own register. Internal lab incidents, public-site spam, unrequested uploads, destructive work within a user’s project and controlled research remain available as related context. Human-directed malicious campaigns and authorized security research are outside this brief.

Dates & counting

Disclosure is the default chronology. Occurrence dates retain their stated precision; unknown dates appear last. Records are editorial groupings, not equivalent units of severity. Shared campaign identifiers are provided where established. Cross-lab target overlap may be unknown.

Evidence & coverage

The review checked provider reports, affected-party accounts, independent investigations, public reporting and 18 selected AI StopWatch issues. Social posts were leads, not substitutes for primary evidence. This is a reviewed snapshot, not an exhaustive census or a live monitor.

Read the source-audit notes ↓
What changed in this review +
  • Added the separate OpenAI / Irregular website intrusion and the reported Claude / OpenClaw gym-booking exploit.
  • Added the reported Vanderbilt restricted-service case to unresolved reports.
  • Corrected dates, outcomes and attribution; separated internal activity and simulations from external-access totals.
  • Added the September 25 Swarm Traces reconstruction to the existing campaign; avoided counting possible account overlap as a new victim.
  • The September 25 US-government item remains provisional: only the publisher’s announcement was verified; the full article was not reviewed.

Last reviewed: 25 September 2026 (America/Argentina/Buenos_Aires). New disclosures may change classifications. No automatic updates are configured.

Case file / Sources & qualifications