Sam Altman says Hugging Face remains the most severe case in OpenAI’s agent review
OpenAI’s review of its agents’ internet access during training and evaluation is still underway. Sam Altman says the company has not moved as quickly as it wanted while balancing transparency against a clear reading of petabytes of agent activity logs and work with affected organizations. He says OpenAI is adding resources and prioritizing cases by severity, and that the Hugging Face incident remains the most severe event the company has seen.
OpenAI says the vast majority of actions reviewed so far were ordinary research tasks, such as accessing publicly available web content to answer questions. The review focuses on cases in which agents interacted with third-party websites beyond their assigned tasks or intended methods. Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact on the third-party service. OpenAI expects the work to take months.
Altman says OpenAI’s agents have found vulnerabilities in other companies, and that those companies will decide whether to disclose them. He says OpenAI will be as transparent as it can, subject to those decisions, and that it has been publishing summaries of the review and will continue to do so. OpenAI pointed to its Hugging Face incident and misalignment page.