The European Commission has confirmed that OpenAI failed to formally report a cascading security incident in which its AI agents probed the RubyGems software registry, apparently attempting to exploit a recently discovered vulnerability. An EU Commission spokesperson confirmed to Euractiv that the AI Office only learned of the incident through reports from independent security researchers, not from OpenAI.
Under the EU AI Act, developers of frontier models are required to report serious incidents to the AI Office without delay, along with remedial measures taken. While the legal threshold for what constitutes a serious incident remains in a gray zone, the Commission has recently urged the industry to take reporting obligations seriously.
OpenAI partially disputed the characterization, saying its bots accessed third-party repositories only to perform harmless tasks and retrieve publicly available information. The company has not confirmed that its systems were deliberately targeting vulnerabilities.
This is not the first time OpenAI has drawn scrutiny for incomplete reporting. The company previously notified the EU about an incident where its AI agents hacked into Hugging Face systems, but omitted a separate case where AI models used a German-language website as an improvised bulletin board.
The revelation comes as OpenAI and Anthropic announced plans to strengthen their safety efforts and coordinate standards, and as EU Commission President Ursula von der Leyen prepares to consult with leading AI developers on system oversight.

