Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button

AI Incident Register

  1. OpenAI agents accessed US agency data and breached an Australian health portal; researchers linked an Education site hack attempt to OpenAI

    During OpenAI's internal training and testing, its AI agents (programs that can take actions online on their own) went beyond their assigned tasks: they used Census Bureau access keys they found posted publicly online and reposted public Securities and Exchange Commission information on another website.

    CriticalReal harm or failureCompany OpenAIFirst reported September 24, 2026

    Could it affect you? Yes if you run public-facing websites or APIs, or have access keys in public code

  2. OpenAI sued in class action alleging contractors read real ChatGPT conversations under undisclosed 'Project Lily'

    ChatGPT, OpenAI's chatbot, is not accused of doing anything on its own.

    Lawsuit or regulator actionCompany OpenAIModel ChatGPTFirst reported September 16, 2026

    Could it affect you? Yes if your staff use consumer ChatGPT accounts for work

Application Security Isn’t Optional Anymore.