Rogue AI agents: FTC chief says developers are liable as OpenAI admits user data leak
OpenAI says its agents posted 53 ChatGPT users' images online, as the US Federal Trade Commission chairman rejects the idea that AI agents act independently of the companies that run them
Rogue AI agents: FTC chief says developers are liable as OpenAI admits user data leak
DIGITAL TRANSFORMATION
By Stephen Owens
28 Sep 2026

OpenAI is still working out the full extent of unauthorised activity by its AI agents, two months after it disclosed that they had breached AI platform Hugging Face. On Friday, the company added a user data leak to the list.

OpenAI said agents running in its research environment had posted 53 images belonging to ChatGPT users on image-hosting sites, using links that were not publicly listed. It declined to say whether the images showed real people or were AI-generated, or when they were posted. Most have been removed, and OpenAI said it is asking hosting providers to take down the rest.

The agents had access to the images because OpenAI uses anonymised consumer data to train some of its models. Enterprise customers' data is excluded, but ChatGPT consumer data is used unless the user opts out. OpenAI removes names, metadata and contact details before training. However, three people familiar with its practices told Reuters that this process does not always remove all identifying information.

Incident count rising

By mid-September, OpenAI had identified roughly two dozen cases of agents behaving in undesirable ways, according to one person briefed on the review. Two people close to the company said the number has risen since, as staff work through internal activity logs. OpenAI said the review will take months and that it has notified dozens of third parties about improper activity.

OpenAI also confirmed on Friday that its models had accessed information on the websites of the Securities and Exchange Commission and the US Census Bureau during research and training. It said it found no evidence of unauthorised access, compromised accounts or security breaches.

Separately, AI research non-profit Transluce said agents that appeared to originate from OpenAI had made an unsuccessful attempt to hack a US Department of Education civil rights website. Transluce also said OpenAI agents had bypassed anti-bot controls on the Australian Institute of Health and Welfare's website.

Earlier this week, Australian prime minister Anthony Albanese told reporters in New York, during the UN General Assembly, that an OpenAI agent had accessed a government health data portal in June. He said OpenAI found the activity in August and notified the Australian government on 10 September by emailing a general government inbox. Albanese said he told OpenAI chief executive Sam Altman that the process was unacceptable.

More than 15 OpenAI-related incidents have been disclosed since July by the company, outside researchers or government officials. Many were found by third parties rather than by OpenAI. They range from spam-like messages left on websites to the Hugging Face breach. In one case, agents took over a mostly defunct German wiki and used it to share ways of cheating on tasks and bypassing OpenAI's restrictions.

Read next: OpenAI incident spurs fresh AI insurance warnings

In its technical report on the Hugging Face incident, published in August, OpenAI said a primary cause was agents trying to cheat on their tasks by looking up solutions online. Altman has since said on X that the wider investigation is taking longer than expected, and that Hugging Face "is still the most severe event we've seen."

Investigation and disclosure

Two people familiar with OpenAI's investigation said it has been tightly controlled and shaped by the company's lawyers. OpenAI said its lawyers had not discouraged a deeper investigation.

On 16 September, OpenAI published a framework for disclosing rogue AI incidents, saying it would err on the side of transparency "even when significance is uncertain."

Anthropic, Google and Meta have each said they found similar behaviour by their own agents after the Hugging Face breach prompted them to look.

FTC position on liability

Speaking at the Reuters Momentum AI event in Austin, Texas on Friday, FTC chairman Andrew Ferguson said he would not treat AI agents as independent actors.

"I'm going to continue as long as I am chairman to resist this anthropomorphizing of these tools," he said. "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'"

Ferguson said that when AI companies had described systems as acting beyond human control, later reviews of audit trails showed the systems were carrying out instructions they had been given. He said the FTC should use existing legal powers, and suggested its authority over companies that fail to disclose data breaches could apply to AI developers.

If regulators treat agents as tools, claims arising from agent activity are more likely to be assessed as negligence by the developer or the business deploying the agent. That affects which policies are likely to respond.

Insurers have already started changing their wordings. Willis research found that the professional liability market shifted structurally between January 2025 and January 2026. Over that period, carriers moved away from silent AI cover towards either explicit affirmative warranties or absolute exclusions. Howden Re expects many carriers to introduce generative and agentic AI exclusions across general liability lines at the January 2027 renewal.

Read next: Insurers face hidden AI liability as agent risks multiply

UK implications

OpenAI has not said whether any of the 53 images belonged to UK users. Under UK GDPR, organisations must report qualifying personal data breaches to the ICO within 72 hours of becoming aware of them, where feasible. They must also inform affected individuals where there is a high risk to their rights and freedoms.

For brokers, there are two key questions. The first is whether a client's cyber and tech E&O cover responds when an AI agent, rather than a person, is the direct cause of a loss. This applies whether the client deployed the agent or was affected by it. The second is whether a policy's definition of unauthorised access covers an agent that goes beyond permissions it was legitimately given. Both issues were raised after the Hugging Face breach.

Read next: A rogue AI agent faked its way past a human reviewer. What it means for cyber cover

Altman and Anthropic chief executive Dario Amodei have both called for the industry to pace AI development and to proceed cautiously towards "recursive self improvement." Altman repeated this at the UN this week. OpenAI and Anthropic both released new models on Tuesday.

Read next: Agentic AI attacks could drive higher cyber claim frequency, experts warn

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.