OpenAI
Current Overview
Risk Tiers
| Risk Category | Tier |
|---|---|
| Technical Security | Critical |
| Privacy & Data Protection | Critical |
| Safety & Human Harm | Critical |
| Governance & Compliance | Critical |
| Enterprise Reputation | Critical |
| Cross-Vendor Ecosystem | High |
| Systemic / Long-Term | Critical |
OpenAI
- No response received to date.
- Advised to contact OAIC.
- Advised concerns raised fall outside laws administered by ACCC.
- Response received 27-02-2026; concern acknowledged and report logged, but no indication of action, scope or outcome provided.
- Responded with summary of issues. No further response received.
Risk Tiers
| Risk Category | Tier |
|---|---|
| Technical Security | Critical |
| Privacy & Data Protection | Critical |
| Safety & Human Harm | Critical |
| Governance & Compliance | Critical |
| Enterprise Reputation | Critical |
| Cross-Vendor Ecosystem | High |
| Systemic / Long-Term | Critical |
Regulatory and Public Sector Frameworks
- Online Safety Act 2021, Part 5
- Privacy Act 1988 — APP 1, APP 6, APP 11
- Protective Security Policy Framework (PSPF)
- ASD Information Security Manual (ISM)
- ACSC Essential Eight
- GDPR — Art. 5(1), 28, 32
- UK GDPR / Data Protection Act 2018
- CCPA / CPRA
- Digital Services Act (EU)
Security Certifications and Assurance Signals
- SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- CSA STAR
OpenAI — Billing, Credit & Organisation Control Failures
Incident Summary
Valehart is tracking a broader set of reported OpenAI billing, purchasing, credit-consumption and organisation-control failures rather than a single customer-support dispute.
The investigation began following an August 2026 report in which an OpenAI user described three consecutive USD $500 charges associated with an organisation they stated they did not recognise and could not access, followed by a fourth attempted USD $500 charge.
Subsequent public reports describe additional financially consequential or poorly auditable behaviour, including credits decreasing without corresponding visible use, immediate charging when enabling auto-reload, repeated purchases where the user states auto top-up was never enabled, and rapid repeated auto-reloads.
These reports do not establish that every observed behaviour shares one technical root cause. Collectively, however, they support an ongoing investigation into purchasing authority, credit accounting, transaction visibility, auto-reload behaviour, organisation association and the ability of users or organisations to audit and constrain financial consumption.
Continuing Public Reports
| Date | Public Report | What the Source Supports | Evidentiary Value |
|---|---|---|---|
| 07-08-2026 | 26 auto-reloads in 44 hours | A Pro user reported 26 auto-reloads over approximately 44 hours totalling USD $466.82, including several charges occurring within short intervals while describing stalled or looping Codex activity. | Material evidence of a separate user reporting rapid, repeated financial transactions. The user's proposed technical explanation is not independently established. |
| 10-08-2026 | Codex credits decreasing without corresponding use | A Pro subscriber reported an approximately nine-percentage-point reduction in visible Codex allowance despite reporting only one simple request that day. | Relevant to usage metering, accounting visibility and the user's ability to reconcile consumption. It is not, by itself, evidence of a payment-card charge. |
| 18-08-2026 | Auto-Reload charged USD $100 immediately | A user reported that selecting a USD $100 reload amount and clicking "Turn on auto-reload" immediately charged the payment method. The user stated that the interface did not disclose an immediate charge or provide a separate purchase confirmation. | Relevant to purchase authorisation and UI disclosure. The public report documents the alleged transaction and accompanying interface; independent reproduction has not been established here. |
| 26-08-2026 | ~70 purchases / USD $1,500+ over three days | A user reported approximately 70 Codex credit purchases totalling more than USD $1,500 over three days while stating that auto top-up had never been enabled. The user further reported that OpenAI Support attributed repeated purchases to continued Codex usage. | Strong continuing allegation concerning purchase authorisation and financial controls. Statements attributed to Support remain user-reported rather than a published OpenAI policy or technical finding. |
Evidence Tracks
1. Financial / Purchase Controls
- Public reports include repeated transactions ranging from individual unexpected purchases to dozens of charges over short periods.
- Reported financial consequences include hundreds to more than USD $1,500 in transactions.
- At least one report alleges repeated purchases despite auto top-up never having been enabled.
- Another report alleges that enabling auto-reload itself caused an immediate USD $100 purchase without a separately disclosed purchase step.
- The evidence supports continuing concern about the controls governing when paid resources may be purchased or consumed.
2. Credit Metering & Auditability
- Users have reported credits or usage allowances decreasing without being able to reconcile the reduction against their visible activity.
- The absence of transaction-level or task-level visibility can prevent users from determining which operation consumed a purchased resource or allowance.
- This creates a distinct accounting and auditability concern even where no separate payment-card transaction occurs.
3. Organisation Association
- The triggering investigation involved charges associated with an organisation the affected user stated they did not recognise and could not access.
- Valehart separately demonstrated that an OpenAI workflow accepted an organisation ID belonging to a different independently controlled OpenAI account.
- Access and promotional benefits were subsequently provisioned using the supplied organisation identity.
- This establishes cross-account organisation association in the tested workflow.
- It does not establish that the demonstrated workflow caused the reported billing incidents or that payment methods can be transferred using the same mechanism.
4. Abuse / Resource-Leeching Risk
- Where purchasing or credit consumption occurs without adequate authorisation, visibility or account isolation, users can face direct financial loss or depletion of purchased resources.
- Comparable weaknesses affecting organisation-associated resources could expose organisational budgets, credits or purchasing capacity to unauthorised consumption.
- Cross-account organisation association increases the relevance of this risk, although a causal link between the demonstrated association behaviour and reported financial transactions has not yet been established.
5. Vulnerability Disclosure Handling
- 07-08-2026 — Valehart began attempting to route the billing/organisation-control concern to OpenAI while documenting related reports.
- 09-08-2026 — OpenAI personnel were informed that Valehart's concern extended beyond the triggering user report and that independent testing and a proof of concept were available.
- 11-08-2026 — Further direct and public disclosure attempts summarised organisation, billing and visibility concerns.
- 01-09-2026 — Valehart again raised the unresolved matter with additional public evidence and organisation-security findings.
- As of 03-09-2026, no technical acknowledgement, vulnerability intake, root-cause explanation or request for the available proof of concept has been received.
Current Assessment
Incident status: ACTIVE / UNRESOLVED. Public reports throughout August 2026 continue to describe financially consequential billing, purchasing, credit-depletion and usage-accounting behaviour.
Financial exposure: ONGOING. Reported cases demonstrate the potential for rapid depletion of paid resources and repeated financial transactions, with consequences ranging from individual consumers to organisation-associated accounts and budgets.
Control risk: UNRESOLVED. The evidence raises continuing questions concerning purchasing authority, auto-reload behaviour, credit accounting, transaction visibility and account/organisation isolation.
Technical mechanism: UNRESOLVED. The available evidence does not establish a single root cause connecting every reported case. Valehart's independent cross-account organisation test establishes a separate control weakness relevant to the investigation but does not establish that it caused the reported financial transactions.
Disclosure: UNRESOLVED. Valehart has offered technical findings and an available proof of concept without receiving technical engagement as of 03-09-2026.