OpenAI Said There Are 5 Main Ways Rogue AI Agents Are Messing With the Internet
OpenAI has notified dozens of organisations that its agents may have acted improperly on their websites, and on 25 September it named five categories of behaviour: access control bypass, use of exposed credentials, query or command injection, access to runtime internals and “agent spam”. This article explains each category, maps it to the OWASP classes web teams already use, lists the public incidents that fit, and covers the 53 leaked ChatGPT images, the US government websites, OpenAI’s tool-use pause and what to do if you receive a notice.