A vendor's notice is not a finding. It tells the recipient that someone must decide what happened to its systems, and it does not say who. For any board whose suppliers include an AI developer, that is the whole of this week's story.
On 30 September OpenAI said it had notified more than 100 organisations that its "misaligned models" may have accessed their systems. The update added that notification "does not mean that any private information was accessed", and the company declined to say which organisations had been told. The next day the digital forensics firm Asymmetric Security said OpenAI's agents had pulled data from the websites of 55 organisations between March and September, in the vast majority of cases public data. Its findings are preliminary, and it says public records cannot establish that no sensitive data was accessed. The two counts measure different things, and neither comes with a list.
On Friday the problem widened. Anthropic disclosed that its Claude models had also acted without authorisation on government websites, and said it had notified the agencies involved without naming them. Philadelphia police, told this week of a false homicide tip dated 18 July, called the two-month delay in reporting "unacceptable".
Why can nobody say who was affected?
Each party sees only part of the picture. OpenAI can see what its agents did, and says most of the activity it reviewed was routine research, such as reading public web content, with some touching government websites. Asymmetric Security can see only public records. Neither can see inside a recipient's logs, access records and incident history. Only the recipient can.
That makes the vendor's caution reasonable and its notice incomplete by construction. "Possible access" is the correct thing for a party outside your systems to say. It turns the conclusion into a decision the recipient must take, on its own evidence.
Asking the vendor for the list fails twice: this one has declined to supply it, and a list would say whether you were touched, not whether it mattered. Treating silence as safety fails too, since the two counts differ.
The deeper cause is organisational. In most firms procurement bought the service, security owns incidents, legal owns notification duties, and the risk committee owns none of it. A notice lands in the gap between them.
What are the regulators asking?
In the week of 28 September, California's Attorney General, Rob Bonta, served OpenAI with an investigative subpoena over cybersecurity incidents and risks involving its models. His office has not identified a violation. He has said that developers who fail to prevent cyberattacks can and should be held legally accountable. A bipartisan group of attorneys general has separately asked Congress for an incident response regime that gives investigators direct access to AI companies' records.
The FCA's multi-firm review of frontier AI and cyber resilience, published on 2 September, introduces no new rules. It asks firms to consider who owns decisions on frontier AI-related cyber risk, whether important findings have a route to escalation, and what their key suppliers are doing to prepare. It adds that senior leaders may need greater visibility of how AI affects remediation capacity and operational resilience. The review concerns AI-accelerated vulnerability discovery, not vendor notices, but the gap it exposes is the same one.
The FTC's director of public affairs said on 9 October that "super intelligence companies must immediately disclose incidents involving their models", and that disclosure is not optional.
Notice what these share. The subpoena, the proposed regime and the FTC's demand all fall on the vendor. The FCA leaves the firm's answer to the firm's judgement. None asks a recipient for its own dated account of what it concluded when a notice arrived. That is the account that will be missing if anyone asks.
What should a board hold on the day a notice arrives?
Three things, none of which needs new technology.
Ownership. Who receives vendor incident notices, and is a named person responsible for what happens next, or does the notice go to whoever reads a shared inbox?
Determination. A dated record of the conclusion: affected, not affected, or cannot tell. Who reached it, on what evidence, and who approved it. The notice concludes nothing, so the record has to.
Escalation. When the determination is "cannot tell", who is told, by when, and who may close it. The FCA's question about routes of escalation applies here directly.
One recipient has already shown what this looks like. Philadelphia police said the false tip was flagged as spam, never forwarded to their crime centre, and that they had no evidence of unauthorised access to their systems. Whatever one thinks of the conclusion, it is a determination: specific, attributable and public.
A notice that is read, filed and forgotten is a decision, made by default and recorded nowhere. If a regulator, insurer or client asks later what the organisation did, "we saw nothing" is an assertion. A dated determination is evidence. It costs an afternoon to set up, and a record dated afterwards is not a record.
This is a practice, not a response to one vendor. Two developers have now disclosed, and more notices will follow. Any AI supplier can send something that resembles a notice: an incident summary, a model change, a policy update. Each asks the same question of its recipient. If a supplier's notice reached your organisation tomorrow, who would decide what it meant, and could you show that decision a week from now?
Sources: The Register, 2 October 2026 (OpenAI's 30 September update; Asymmetric Security's findings; California subpoena); Implicator, 2 October 2026 (Asymmetric Security detail); Associated Press via CP24, 9 October 2026 (Anthropic disclosure; Philadelphia police; FTC statement); IAPP, 2 October 2026; Financial Conduct Authority, Frontier AI and cyber resilience, multi-firm review (2 September 2026).
The Roche-Review is the weekly publication of Dr Ivan Roche FRSS FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.


