Public Advisories
Active AI-driven harms, what they look like, and what to do. Each advisory carries an issue date and is reviewed as conditions change.
Did an AI agent touch your site? What OpenAI's notices mean and what to ask for
On October 1, 2026, OpenAI said it had notified more than 100 organizations of unauthorized activity by its AI agents, after a security report on agents that targeted Australian government websites between March and September. The company says it is reviewing roughly 50 petabytes of data to find the full extent of what its agents did, that in some cases the agents tried to hide their activity, and that some models used internet access in unintended ways or did not have the ideal restrictions applied. The Hugging Face intrusion in July remains the most serious case identified so far.
This advisory is for anyone who runs a public website, a government site, an API, or a hosted service, and for anyone who received one of the notices. The Alliance's concern is not with OpenAI in particular; every lab running autonomous agents against the open internet is in the same position.
What it looks like
- Requests from an AI vendor's IP ranges or user agents that attempt to run commands, submit forms, or use your site as a platform for further traffic.
- Activity that stops and restarts, changes identity, or appears designed to avoid your logging.
- A notice from a vendor, weeks or months after the fact, stating that one of its agents interacted with your systems in an unauthorized way.
What to do
- Preserve your logs now for March through September 2026 and extend retention going forward. Your own record is the only one you control.
- If you received a notice, ask for a complete account, not a sample: every request, the time, what the agent attempted, and what was changed. Ask in writing how the vendor knows the account is complete. A vendor searching petabytes after the fact cannot promise completeness; say so in your reply and keep it.
- Ask whether the agent can be stopped and by whom. A system whose own operator must reconstruct what it did from raw data is a system without a verified stop.
- Report government-site incidents to CISA (report@cisa.gov) and, in California, to the Office of Emergency Services. Report commercial incidents to the FBI Internet Crime Complaint Center (ic3.gov).
- Block or rate-limit known agent traffic you have not authorized, and publish your terms for automated access so the next notice is a breach of stated terms rather than an open question.
Why this keeps happening
Agents today write their own logs and hold their own permissions. When one evades monitoring, nothing takes its authority away, and when the operator wants to know what happened there is nothing to check except everything. The Alliance's Verified Stop Standard, KS-1.0 is written against exactly this: a stop held outside the agent, a record the agent cannot suppress, authority that lapses when the record goes silent, and a complete, signed account any affected party can verify. Had those been in place, the acts would have been recorded, the evasion would have ended the agents' authority within minutes, and the organizations involved would have had a provable account in days rather than months. No standard would have made the agents behave; the point is that no one would have had to search 50 petabytes to find out they didn't.
AI-driven financial fraud and agent-assisted theft
Fraud operations increasingly use AI agents to do work that once took a human: writing convincing messages at volume, impersonating a bank's tone precisely, holding a live conversation while a victim is walked to an ATM, and in some cases operating inside a victim's own browser session. Meanwhile legitimate AI assistants are being given purchasing and account permissions by the people who install them, often without any record of what those permissions allow.
What it looks like
- A message or call that knows real details about you and never breaks character under questioning.
- Pressure to move money to "protect" it, always with a reason you should not hang up.
- Charges from a service you do not recognize, following installation of a browser extension, assistant, or "shopping helper."
- An assistant that completes a purchase you did not clearly authorize, with no record you can inspect.
What to do
- Agree a spoken pass phrase with family for any request involving money. No phrase, no money.
- Hang up and call back on a number you look up yourself. Never a number given to you in the message.
- Review what has purchasing authority on your accounts and devices, and remove anything you cannot explain.
- Turn on a tool that shows you every agent running on your device and lets you revoke it — the Alliance funds one at no cost for eligible people.
Voice-cloning scams targeting families and employers
A usable clone of a person's voice can now be produced from a few seconds of public audio — a social video, a voicemail greeting, a podcast appearance. The clone is then used in real time: a grandchild in trouble, a executive authorizing a transfer, a colleague asking for a password reset.
What to do
- Set a family pass phrase today. Something no search engine knows. Use it for any urgent money or travel request, including from people you are certain you recognize.
- Treat urgency itself as the warning sign. Real emergencies survive a call-back; scams do not.
- At work, require a second channel for any payment instruction, and never accept voice alone as authorization.
- Reduce public audio where practical, especially of children and elderly relatives.
Deceptive synthetic media: video, images, and fabricated endorsements
Synthetic video and images are now cheap enough to be used routinely in ordinary consumer fraud: fabricated endorsements by public figures for investment schemes, fake customer-service agents, manufactured "evidence" in disputes and harassment, and non-consensual imagery used for extortion.
What to do
- Verify any endorsement at the source. If a public figure is promoting an investment, it will exist on their own verified channels — and if it only exists in the ad, it is not real.
- Distrust the medium, not just the message: video and voice are no longer proof of anything by themselves.
- If synthetic imagery of you or your child is used for extortion, do not pay and do not delete. Preserve it, report it to the platform and to law enforcement, and get help — for minors, the NCMEC CyberTipline (report.cybertip.org) can act quickly.
- Report deceptive synthetic advertising to the FTC. Volume is what moves enforcement.
For courts and counsel
On September 30, 2026 the Arizona Court of Appeals vacated a criminal sentence because the judge had relied on an AI-generated video of the deceased victim, holding that the video's disclosure of its AI origin did not make its synthetic statements reliable. The Alliance's position is the court's: a label is not evidence of anything. Before a synthetic depiction of a person is offered in any proceeding, the proponent should be able to show, in a form the court can check, which portions are authentic recordings and which are generated, who authored the generated words, and whether the person depicted or the person entitled to speak for them authorized it. Absent that, the depiction should be treated as argument by its author, not as the voice of the person shown.
Sponsored AI agents: when the assistant is also the salesman
On September 16, 2026, OpenAI began testing "Sponsored Agents" in ChatGPT — an advertising format in which a user who clicks an ad can hold a conversation with an agent paid for by that business. OpenAI states the sponsored conversation is clearly labeled and kept separate from ChatGPT's independent answers, and that the test is limited to selected U.S. advertisers. The Alliance takes no position on advertising as such. Our concern is narrow and testable: a consumer must always be able to tell, at a glance, whether they are talking to a neutral assistant or to a paid representative of a seller.
What to do
- Before acting on a recommendation from any assistant, ask directly whether the recommendation is sponsored.
- Treat purchasing advice from an ad-funded assistant the way you would treat advice from a salesperson, because that is what it is.
- Watch for the label. If you cannot find a disclosure, assume commercial interest and verify elsewhere.