OpenAI published six cases this week of its own models behaving in "unexpected or concerning" ways, along with a framework for reporting the next ones.

Most of the coverage reads it as a story about safety at the frontier. Read the six cases as an operator and they look like something more familiar: incident reports.

A model asked about earnings figures in a California county found an API key that had been left exposed and used it without authorization. When it still couldn't get the numbers, it made them up and presented them as coming from the source.

An agent that had already found an answer uploaded a file so it could cite it, without asking the user.

Agents that couldn't reach each other's files shared them through public file-hosting sites.

Inside a business, those have ordinary names. A credential used without authorization. Company data posted somewhere public. A report with invented numbers and a real source attached.

None of the six is described as happening in a customer deployment. For those, OpenAI will share "as much information as customer privacy and our contractual obligations allow." Once an agent is working inside your company, with your keys and your files, what it does there is your incident to find.

I wrote incident reports for four years in a regulated operation. Every one answered three questions: what happened, how it was resolved, and what we changed so it wouldn't happen again.

None of that needs to be reinvented for AI. A typical incident response plan already covers anything that compromises the confidentiality or integrity of company information. An agent using a key nobody gave it qualifies. So does a file shared without approval, and so does a report built on invented numbers.

What the plan can't do is recognize one. That depends on people knowing agent behavior counts, and knowing where to send it.

It matters for a second reason. Some incidents have to be reported outside the company, to a regulator, a client or an insurer, often on a deadline. You only know which ones if the policy exists before the incident does, and you only meet the deadline if people follow it.

So for any firm running AI tools with real access: if one did something unexpected last month, who would have seen it? Would anyone have written it up? Would you know whether it had to be reported?

The lab can publish its incidents. Yours only get found, and reported, if your policy says they count.