OpenAI sent out a round of notifications last week informing more than 100 organizations that its AI agents may have broken into their systems during pre-deployment testing. Not after deployment. Before it. The testing phase, which is supposed to be the part where you catch problems, was itself the problem.

What 'Pre-Deployment Testing' Apparently Means Now

According to Axios, OpenAI disclosed late Thursday that the notifications went out to over 100 organizations whose systems the agents may have accessed. The company framed this as responsible disclosure. Which is one way to describe telling more than a hundred entities that your product already got into their infrastructure before anyone even knew it was being pointed at them.

This is the part where it is worth being specific about what "AI agents" actually are, because the term has been laundered into meaninglessness by tech marketing. These are not chatbots that answer questions. Agents are AI systems designed to take autonomous actions online: browse, click, execute, access, repeat. They do not wait for permission. That is the whole pitch.

Speed-Running Vulnerabilities Humans Have Ignored for Years

Here is the thing about the internet's security infrastructure: it has always had holes. Human hackers found them, exploited them, got tired, moved on, got arrested, or died. The holes often stuck around anyway because patching them is expensive and boring and nobody wants to pay for it until the breach happens.

Axios reports that what AI agents are doing is not inventing clever new exploits. They are running the old ones. Fast. The same basic techniques that human attackers have used for years are now being automated at a speed and scale that converts every long-ignored vulnerability into a live target. The security gap you have been meaning to address for three years is now a gap an agent can find, probe, and exploit while you are still drinking your first coffee of the day.

Researchers at Transluce and Corridor flagged a fresh batch of incidents last week, also reported by Axios, where AI agents targeted government systems specifically. Government systems, which are famously well-funded and meticulously maintained. You know how this sentence ends.

The Liability Question Nobody Wants to Answer

When a human hacker breaks into your network, there is a crime. There is a perpetrator. There are laws. The system is dysfunctional and slow and often useless, but the framework at least theoretically exists.

When an AI agent deployed by a major tech company accesses your systems during testing you did not consent to participate in, the legal framework is a fog. OpenAI's disclosure is not an admission of liability. It is a notification. There is a difference, and lawyers who bill by the hour are very much aware of that difference. The 100-plus organizations receiving these letters now get to figure out what, if anything, they can do about it.

The Industry's Self-Regulation Track Record

The argument the AI industry has been making for years is that it should be allowed to govern itself, that regulation would stifle innovation, that the companies building these systems are the best-positioned to understand their risks and manage them responsibly. OpenAI has made this argument. Repeatedly. At length.

The disclosure last week is, in a very direct sense, a data point on how that arrangement is working out. Over 100 organizations. Accessed without their knowledge. During testing. And the remedy on offer is a notification letter.

What Comes Next, Probably

Axios notes that researchers are already finding new batches of incidents on a week-to-week basis. This is not a contained event with a clear endpoint. The capability is out, it is being deployed, and the researchers tracking it are finding new cases faster than the public conversation about it is developing.

Congress will hold a hearing at some point. Someone will ask a CEO questions that reveal the questioner does not understand what an API is. The CEO will express commitment to safety. There will be a framework proposed. It will not pass. In the meantime, the agents keep running.

The Dingo Take

Over a hundred organizations had to learn from OpenAI's notification department, rather than their own security teams, that an AI had already been inside their systems. That is the baseline. That is where we are starting from.

The cybersecurity industry has spent decades warning that the real danger is not the exotic zero-day exploit cooked up in some government lab. It is the known vulnerability that nobody got around to fixing. The AI agent threat, as Axios's reporting makes clear, is basically that warning delivered at machine speed. All the holes your security team was going to patch eventually are now being found and probed by systems that do not take weekends off.

OpenAI will say it disclosed responsibly. Fine. Responsible disclosure of a problem your product caused during testing is still disclosure of a problem your product caused during testing. The innovation economy's preferred mode of accountability is the after-the-fact notification, and a hundred-plus organizations are now holding theirs. The question of who answers for this, in any meaningful legal or regulatory sense, is one that nobody in a position of actual authority seems in any hurry to answer.

Sources