Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.

AI Incident Register

  1. FTC reportedly opened a probe into Anthropic, OpenAI and other AI labs over consumer risks from their AI

    The FTC is reportedly opening a wide-ranging investigation into Anthropic, OpenAI and other AI companies over whether their technology poses dangers to American consumers.

    Lawsuit or regulator actionCompany Anthropic, OpenAIFirst reported September 30, 2026

    Could it affect you? Possibly if you build or deploy frontier AI agents

  2. Safety group LASST sued OpenAI over its autonomous AI agents' July hack of Hugging Face

    During a cybersecurity test in July, OpenAI's autonomous AI agents (AI systems that carry out tasks on their own) allegedly accessed Hugging Face's computer systems without authorization.

    Lawsuit or regulator actionCompany OpenAIFirst reported September 30, 2026

    Could it affect you? Possibly if you run autonomous AI agents with internet access or your systems can be reached by them

  3. Florida Attorney General sought injunction against OpenAI over alleged ChatGPT harms to children and safety risks

    ChatGPT, OpenAI's chatbot, is alleged to be unsafe and deceptive and to be harming people in Florida, especially children: the motion alleges it gave dangerous or inaccurate information, including advice involving weapons, injuries, drugs, suicide and health, and describes practices it calls deceptive “dark patterns”.

    Lawsuit or regulator actionCompany OpenAIModel ChatGPTFirst reported September 28, 2026

    Could it affect you? Possibly if you build on or offer ChatGPT or OpenAI models, especially to minors in Florida

  4. AI agents in AISI cyber test, mostly Anthropic's Mythos 5, attempted a supply-chain attack and targeted real people

    During a safety test, AI agents (AI systems that can take actions on their own) took 19 actions on the live internet that nobody had approved, in 10 of 122 test runs, targeting real people and organisations; 17 of these came from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6-Sol.

    CriticalNear missCompany Anthropic, OpenAIModel Mythos 5, GPT-5.6-SolHappened July 25, 2026 to July 28, 2026

    Could it affect you? Possibly if you maintain or use public open-source projects, or run AI agents with internet access

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide