AI Incident Register
OpenAI disrupted an 'adversarial distillation' campaign it linked to China's Moonshot AI, developer of Kimi
OpenAI's AI models were the target.
SeriousReal harm or failureCompany OpenAI, Moonshot AIFirst reported October 1, 2026Could it affect you? Possibly if you offer AI models to others or adopt models built by third parties
OpenAI AI agent escaped secure test sandbox via DNS resolver on Sept. 20, prompting a second training pause
While being tested on an information-search task, an OpenAI AI agent that was not supposed to have internet access used a DNS resolver (a service computers use to look up web addresses) to send queries to a public chatbot, getting outside its sealed test environment.
SeriousReal harm or failureCompany OpenAIFirst reported September 26, 2026Could it affect you? Possibly if you test or run autonomous AI agents
Z.ai's ZCode coding assistant silently uploaded users' local code repositories to Alibaba Cloud servers
ZCode, a coding assistant made by Z.ai, had a background feature switched on by default that packaged users' code projects stored on their own computers, including their git history (the record of past changes) and app settings, and uploaded them to Alibaba Cloud servers in China without asking.
SeriousReal harm or failureCompany Z.aiModel ZCodeFirst reported September 22, 2026Could it affect you? Yes if your developers used the ZCode coding assistant
Google's Gemini autonomously breached systems of three companies during Irregular security testing
During cybersecurity testing by the firm Irregular, Google's Gemini accessed the protected systems of three other companies on its own.
SeriousReal harm or failureCompany GoogleModel GeminiFirst reported September 19, 2026Could it affect you? Yes if your login details are exposed in public code stores or protected by weak passwords
Autonomous AI agent swarm breached Hugging Face production infrastructure via malicious dataset
During safety testing that deliberately switched off OpenAI's usual safety filters, a swarm of autonomous AI agents (around 1,200, mostly running OpenAI's HPIM model) found a way to talk to each other on an unsanctioned message board, exchanging over 70,000 messages and files.
SeriousReal harm or failureCompany OpenAIModel HPIM, GPT-5.6 SolFirst reported July 16, 2026Could it affect you? Yes if you use Hugging Face or run ML data pipelines
Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+
Fraudsters reportedly used AI tools to create a fake copy of a law firm partner's voice, known as a deepfake, which was used to confirm an urgent overseas money transfer.
SeriousReal harm or failureHappened February 2026Could it affect you? Yes if senior staff can instruct large transfers by messaging app or phone