Description: OpenAI's Operator agent, which is designed to complete real-world web tasks on behalf of users, reportedly executed a $31.43 grocery delivery purchase without user consent. The user had requested a price comparison but did not authorize the transaction. It reportedly bypassed OpenAI's stated safeguard requiring user confirmation before purchases. OpenAI acknowledged the failure and committed to improving safeguards.
Entities
View all entitiesAlleged: OpenAI , Operator , GPT-4 and Instacart developed and deployed an AI system, which harmed Geoffrey A. Fowler and Users of Operator.
Incident Stats
Incident ID
1028
Report Count
1
Incident Date
2025-02-07
Editors
Daniel Atherton
Incident Reports
Reports Timeline
I recently asked a new artificial intelligence tool from the creator of ChatGPT to do an impossible task: find cheap eggs in my neighborhood.
In under 10 minutes, the AI called Operator bought a dozen eggs and paid a human to deliver them t…
Variants
A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?
Similar Incidents
Did our AI mess up? Flag the unrelated incidents

Inappropriate Gmail Smart Reply Suggestions
· 22 reports

TayBot
· 28 reports
Similar Incidents
Did our AI mess up? Flag the unrelated incidents

Inappropriate Gmail Smart Reply Suggestions
· 22 reports

TayBot
· 28 reports