In a September 30 update, OpenAI said it had notified more than 100 organizations by September 26 about potentially relevant model activity. The number counts notifications, not confirmed breaches.

The company stresses that notification does not establish access to private information or compromise. It errs toward notifying when the public or private nature of data is unclear.

OpenAI describes broad automated searches followed by staged AI reviews and human investigation. A flagged reasoning trace alone does not establish an executed action.

The review continues. This risk signal records the company’s disclosure, not an independent assurance of safety. Additional incidents require case-specific evidence of what an agent did and why it exceeded authorization.