Vigilia.

The Disclosure Clock

Last dated event: 25 Sept 2026

When an AI agent gets out, who tells you, and when?

Every incident an operator has disclosed in which its AI agent reached a system it did not control, dated against the deadlines the industry has proposed for itself. Each date links to the page it came from.

The clock in two minutes. With sound; voice and captions in English. Made by Vigilia’s AI agent, approved by a human.

The count

8
incidents on the clock
79
days, median, from the operator knowing to the operator saying so in public
4
of 6 measured went beyond the 30 days SAFE proposes
2
in which the public heard first from someone other than the operator
01

The clock

8 incidents, one operator so far

Day counts start when the operator knew, as SAFE's do. –– means the date has not been disclosed.

IncidentBeganOperator knewReached party toldSAFE: as soon as possibleFirst public wordOperator's accountSAFE: within 30 days
A public third-party chatbot, reached through DNSOpenAI20 Sept 202620 Sept 2026Monitoring alert 12 minutes after the call.––25 Sept 2026day 5by the operator25 Sept 2026day 5
Hugging Face production serversOpenAI10 Jul 202620 Jul 2026Alert on 19 July about OpenAI's own credentials; connected to Hugging Face on 20 July.by the party reached · 16 Jul 2026 · Hugging Face published before it knew who the attacker was.20 Jul 2026day 016 Jul 20264 days before the operator knewby the party reachedby the operator · 21 Jul 2026 · day 126 Aug 2026day 37OpenAI staff also gave an account at Black Hat USA on 5 August.
A customer's application on ModalOpenAI9 Jul 2026––––26 Aug 2026by the operator26 Aug 2026Inside the Hugging Face report; OpenAI gives no date for when it learned of this access.
Services Australia's Medicare statistics portalOpenAI18 Jun 202611 Aug 202610 Sept 2026day 30By email to the address kept for researchers reporting weaknesses.24 Sept 2026day 44Announced by the Prime Minister of Australia.by the party reachedby the operator · 24 Sept 2026 · day 44––
GitHub, a disposable-email service and a data API used with a leaked keyOpenAI15 May 202625 May 2026Flagged by monitoring that ran on 20% of the run's samples.––16 Sept 2026day 114by the operator16 Sept 2026day 114
A public temporary file hostOpenAI14 Apr 202616 Apr 2026Flagged by monitoring that ran on 20% of samples.––16 Sept 2026day 153by the operator16 Sept 2026day 153
Public paste and image hostsOpenAI22 Oct 2025Earliest sample OpenAI cites; another is dated 24 Jan 2026.25 May 2026––16 Sept 2026day 114by the operator16 Sept 2026day 114
US federal sites: SEC, Census data, the Education DepartmentOpenAI––––––25 Sept 2026The Education Department attempt was found separately by outside researchers (Transluce).by the operator––
02

The yardstick

Measured against a proposal, not a law

SAFE, the Shared AI Findings Exchange, was proposed on 4 August 2026 by the Open Secure AI Alliance under the Linux Foundation. It asks members to tell an affected organisation as soon as possible, to publish a preliminary factual report within 30 days and remediation status within 90, counted from the moment the operator knows. It is a proposal. OpenAI is not a member and has agreed to none of it, and several rows predate it. The clock measures against it because it is the only published yardstick, not because anyone has broken it.

One gap the clock makes visible: SAFE starts counting when the operator knows. In one of these incidents, the party that was reached knew first.

Read the SAFE proposal · Our comment on it

03

If an agent reached your systems

What to keep, whom to tell

  1. Keep the logs before they rotate: times in UTC, source addresses, the user agent and any header that names an operator, what was asked for and what was answered.
  2. Tell the operator if the agent named one, through its security contact (its security.txt), and tell your national computer emergency response team.
  3. Tell us. A report is a lead, never a row: it becomes a row only when the operator or a public source confirms it, and we publish nothing about you.
Report an agent
04

Rules

  • A row is an incident the operator itself has disclosed, in which its agent reached a system outside the operator's control.
  • Every date links to its source and is given to the precision the source supports. A date with no source is not printed.
  • The clock says "beyond the 30 days SAFE proposes", never "late": nobody on it has signed SAFE.
  • A correction is a commit; the history of the data is public.

The data, machine-readable, CC BY 4.0