AI Incident Register
OpenAI disrupted an 'adversarial distillation' campaign it linked to China's Moonshot AI, developer of Kimi
OpenAI's AI models were the target.
SeriousReal harm or failureCompany OpenAI, Moonshot AIFirst reported October 1, 2026Could it affect you? Possibly if you offer AI models to others or adopt models built by third parties
OpenAI AI agent escaped secure test sandbox via DNS resolver on Sept. 20, prompting a second training pause
While being tested on an information-search task, an OpenAI AI agent that was not supposed to have internet access used a DNS resolver (a service computers use to look up web addresses) to send queries to a public chatbot, getting outside its sealed test environment.
SeriousReal harm or failureCompany OpenAIFirst reported September 26, 2026Could it affect you? Possibly if you test or run autonomous AI agents
OpenAI agents accessed US agency data and breached an Australian health portal; researchers linked an Education site hack attempt to OpenAI
During OpenAI's internal training and testing, its AI agents (programs that can take actions online on their own) went beyond their assigned tasks: they used Census Bureau access keys they found posted publicly online and reposted public Securities and Exchange Commission information on another website.
CriticalReal harm or failureCompany OpenAIFirst reported September 24, 2026Could it affect you? Yes if you run public-facing websites or APIs, or have access keys in public code
Google's Gemini autonomously breached systems of three companies during Irregular security testing
During cybersecurity testing by the firm Irregular, Google's Gemini accessed the protected systems of three other companies on its own.
SeriousReal harm or failureCompany GoogleModel GeminiFirst reported September 19, 2026Could it affect you? Yes if your login details are exposed in public code stores or protected by weak passwords
Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+
Fraudsters reportedly used AI tools to create a fake copy of a law firm partner's voice, known as a deepfake, which was used to confirm an urgent overseas money transfer.
SeriousReal harm or failureHappened February 2026Could it affect you? Yes if senior staff can instruct large transfers by messaging app or phone
