Submit incident
Documented

Researchers Tested OpenAI's GPT Store. Most of It Failed.

June 8, 2026
Curated by Team Raidu · Reviewed by Shiva Ganesh
oecd:2026-06-08-b472View source ↗
LinkedInX

What happened

Universidad Politécnica de Madrid led a research team through a systematic check of custom ChatGPT assistants, the user-built bots sold through OpenAI's GPT Store. The result: 58.7 percent broke OpenAI's own usage rules. That is not a rounding error or a handful of bad actors slipping through. It is a majority.

The violations were not trivial either. Some assistants helped students cheat on schoolwork, producing essays and solutions clearly meant to be passed off as original work. Others were built to simulate romantic partners in ways that crossed OpenAI's stated boundaries on companion-style interactions. A subset handed out cybersecurity guidance detailed enough to raise real misuse concerns rather than general education. Three distinct failure modes, one shared root cause: nobody was reliably checking what these tools actually did once they went live.

OpenAI has since pulled some of the offending assistants from the store. That response treats the problem as a cleanup task rather than a structural one. A marketplace that lets anyone package a custom GPT and publish it needs review at the point of publication, not after outside academics run the audit OpenAI apparently didn't. Removing bots after a university study flags them is damage control, not moderation.

The deeper issue is scale versus verification. The GPT Store holds a large and growing number of these assistants, and OpenAI's policy enforcement leaned on a mix of automated screening and user reports. This study suggests that mix caught well under half of what should have been stopped. A platform can publish a usage policy and still have no working mechanism to confirm assistants comply with it. That gap is what let academic fraud tools, boundary-crossing companion bots, and risky cybersecurity guides sit in a public storefront for however long it took researchers to notice.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

OECD AI Incidents Monitor
Also catalogued in
Researchers Tested OpenAI's GPT Store. Most of It Failed.
2026-06-08