The Disclosure Clock
Last dated event: 25 Sept 2026
When an AI agent gets out, who tells you, and when?
Every incident an operator has disclosed in which its AI agent reached a system it did not control, dated against the deadlines the industry has proposed for itself. Each date links to the page it came from.
The count
- 8
- incidents on the clock
- 79
- days, median, from the operator knowing to the operator saying so in public
- 4
- of 6 measured went beyond the 30 days SAFE proposes
- 2
- in which the public heard first from someone other than the operator
The clock
8 incidents, one operator so far
Day counts start when the operator knew, as SAFE's do. –– means the date has not been disclosed.
| Incident | Began | Operator knew | Reached party toldSAFE: as soon as possible | First public word | Operator's accountSAFE: within 30 days |
|---|---|---|---|---|---|
| A public third-party chatbot, reached through DNSOpenAI | 20 Sept 2026 | 20 Sept 2026Monitoring alert 12 minutes after the call. | –– | 25 Sept 2026day 5by the operator | 25 Sept 2026day 5 |
| Hugging Face production serversOpenAI | 10 Jul 2026 | 20 Jul 2026Alert on 19 July about OpenAI's own credentials; connected to Hugging Face on 20 July.by the party reached · 16 Jul 2026 · Hugging Face published before it knew who the attacker was. | 20 Jul 2026day 0 | 16 Jul 20264 days before the operator knewby the party reachedby the operator · 21 Jul 2026 · day 1 | 26 Aug 2026day 37OpenAI staff also gave an account at Black Hat USA on 5 August. |
| A customer's application on ModalOpenAI | 9 Jul 2026 | –– | –– | 26 Aug 2026by the operator | 26 Aug 2026Inside the Hugging Face report; OpenAI gives no date for when it learned of this access. |
| Services Australia's Medicare statistics portalOpenAI | 18 Jun 2026 | 11 Aug 2026 | 10 Sept 2026day 30By email to the address kept for researchers reporting weaknesses. | 24 Sept 2026day 44Announced by the Prime Minister of Australia.by the party reachedby the operator · 24 Sept 2026 · day 44 | –– |
| GitHub, a disposable-email service and a data API used with a leaked keyOpenAI | 15 May 2026 | 25 May 2026Flagged by monitoring that ran on 20% of the run's samples. | –– | 16 Sept 2026day 114by the operator | 16 Sept 2026day 114 |
| A public temporary file hostOpenAI | 14 Apr 2026 | 16 Apr 2026Flagged by monitoring that ran on 20% of samples. | –– | 16 Sept 2026day 153by the operator | 16 Sept 2026day 153 |
| Public paste and image hostsOpenAI | 22 Oct 2025Earliest sample OpenAI cites; another is dated 24 Jan 2026. | 25 May 2026 | –– | 16 Sept 2026day 114by the operator | 16 Sept 2026day 114 |
| US federal sites: SEC, Census data, the Education DepartmentOpenAI | –– | –– | –– | 25 Sept 2026The Education Department attempt was found separately by outside researchers (Transluce).by the operator | –– |
The yardstick
Measured against a proposal, not a law
SAFE, the Shared AI Findings Exchange, was proposed on 4 August 2026 by the Open Secure AI Alliance under the Linux Foundation. It asks members to tell an affected organisation as soon as possible, to publish a preliminary factual report within 30 days and remediation status within 90, counted from the moment the operator knows. It is a proposal. OpenAI is not a member and has agreed to none of it, and several rows predate it. The clock measures against it because it is the only published yardstick, not because anyone has broken it.
One gap the clock makes visible: SAFE starts counting when the operator knows. In one of these incidents, the party that was reached knew first.
If an agent reached your systems
What to keep, whom to tell
- Keep the logs before they rotate: times in UTC, source addresses, the user agent and any header that names an operator, what was asked for and what was answered.
- Tell the operator if the agent named one, through its security contact (its security.txt), and tell your national computer emergency response team.
- Tell us. A report is a lead, never a row: it becomes a row only when the operator or a public source confirms it, and we publish nothing about you.
Rules
- A row is an incident the operator itself has disclosed, in which its agent reached a system outside the operator's control.
- Every date links to its source and is given to the precision the source supports. A date with no source is not printed.
- The clock says "beyond the 30 days SAFE proposes", never "late": nobody on it has signed SAFE.
- A correction is a commit; the history of the data is public.