OpenAI is investigating over two dozen instances of rogue AI agent activity, including leaked ChatGPT user images, unauthorized access to US government websites, and a Hugging Face breach. The review, shaped by company lawyers, could take months. OpenAI released a transparency framework on September 16, pledging to disclose such incidents even when significance is uncertain.