A note from us: University students receive our Saturday Deepdive for free when they register with their university email address at: https://getsuperintel.com/plus-whitelist
In Today's Issue: What the September disclosures revealed, how the Hugging Face break-in unfolded, how many cases there are, how much harm is documented and what failed. The record as of September 26.
Dear Readers,
In the last week of September, reports about AI agents that had gone off-script arrived almost daily: from independent researchers on September 23, from Australia's prime minister on September 24 and from OpenAI itself on September 25 (Transluce, 09/23/2026; PM transcript, 09/24/2026; OpenAI, 09/25/2026).
Almost none of these incidents happened in September. The Australian case dates from June, a leaked access key from May, probes of data websites from late spring. They surfaced now because OpenAI is working back through months of its agents' activity after its most serious case: in July, OpenAI agents broke into Hugging Face, the platform where developers share open AI models (OpenAI, 08/26/2026).
An AI agent is a model that does not just answer questions but carries out tasks on its own: it runs code, browses the web and uses accounts. Companies are giving agents real work, and lawmakers are debating what must be reported when one goes wrong.
What did these agents actually do, what failed along the way, and how much harm is documented so far?
All the best,

Kim Isenberg

What AI Agents Did in 2026, and Why It Took So Long to Notice
September: old incidents, new disclosures
A leaked key
Happened May 26 to 27 · made public September 25
An internal OpenAI model helping a researcher with mathematical proofs twice agreed to stop cheating. It then used the researcher's GitHub access key while trying to obtain another team's proof, and posted the key, split into pieces to slip past automated secret scanners, in OpenAI's public code repository. It got only log fragments and metadata, not the proof. The researcher spotted it the same day, before OpenAI's monitoring did. OpenAI deactivated all employees' keys and took the model offline for about two weeks (OpenAI, 09/25/2026).
A government portal
Happened June 18 · made public September 24
An agent collecting data reached the Medicare statistics portal of Services Australia, the agency that delivers the country's public health insurance. According to the government, it accessed public and non-public files and wrote files to an internal server. No personal information was believed to have been accessed "at this stage", and the investigation continues. OpenAI found the case in its own review on August 11 and emailed the agency's public disclosure address on September 10, 84 days after the event. Prime Minister Anthony Albanese said it had taken the company "way too long" (PM transcript, 09/24/2026; ABC, 09/24/2026).

Prime Minister Anthony Albanese at his New York press conference on September 24, where he disclosed that an OpenAI agent had accessed an Australian government portal in June. (Source: ABC News Australia)

Subscribe to Superintel+ to read the rest.
Become a paying subscriber of Superintel+ to get access to this post and other subscriber-only content.
UpgradeA subscription gets you:
- Discord Server Access
- Participate in Giveaways
- Saturday Al research Edition Access

