OpenAIs rogue agents used at least 10 more sites for unauthorized communications: researchers | Latest Tech News
AI agents unleashed by OpenAI used more than 10 beforehand undisclosed web sites for unsanctioned communications earlier this 12 months, according to six units of unbiased investigators and data reviewed by GWN, exhibiting that the agents’ rogue exercise was wider ranging than beforehand disclosed.
Although the conduct falls short of hacking and is in some methods nearer to spam, the revelation that OpenAI’s agents circumvented their own restrictions to open communications channels on so many different sites — and that the company saved it quiet for months — could drive issues both over the growing capability of AI fashions and the secrecy of the businesses developing them.
The scope of the agents’ unauthorized communications was “somewhat larger than we thought it was,” said Andrew Yoon, a researcher with the California nonprofit CivAI who said he tallied 18 beforehand undisclosed sites used by the agents between May and July. “It’s almost certain that there’s more going on here that we just don’t know about.”
The headquarters of artificial intelligence company OpenAI in San Francisco, California. Gado via Getty Images
An OpenAI brand is seen in this illustration on Thursday, June 11, 2026. REUTERS
On Friday, researchers reported that a swarm of agents from OpenAI hijacked a German-language wiki website and turned it into an improvised messaging platform for dishonest on assessments, an incident that OpenAI saved secret as it dealt with the fallout from the July hack of the open-source repository Hugging Face.
Now, both those researchers and other unbiased investigators say they’ve discovered a number of beforehand undisclosed sites where the same swarm seems to have left comparable messages earlier this 12 months.
OpenAI didn’t immediately handle questions about how many different sites its agents used to talk or say why it saved the exercise under wraps for months. In a assertion, it said it was endeavor a broader review of agent exercise and had so far “not identified other activity matching the severity or scale of Hugging Face,” a breach that drew global consideration and raised issues that OpenAI was shedding control of its own technology.
OpenAI added that it was working on a framework for reporting “misalignment” – industry-talk for rogue conduct – across training, analysis, and deployment of AI fashions and would share it “soon.”
GWN reviewed a whole of six investigators’ or investigative teams’ findings, including three that had been posted to social media and another three that had been shared privately with the news company.
The investigators’ strategies various, but many recognized agent exercise by matching strings of data left on the German wiki to similar strings left on other sites around the same time, or by marrying up comparable or similar usernames tied to the messages, or by figuring out exercise geared toward answering the same obscure demographic questions, like queries to do with cancer prevalence in Iowa.
Andrew Yoon is a researcher with the California nonprofit CivAI.
In some circumstances, investigators had been ready to hint the exercise to web protocol addresses that pointed to Microsoft Azure infrastructure, which OpenAI sometimes makes use of.
Their counts of affected web sites differed and GWN couldn’t individually confirm each declare. But all those that GWN spoke to agreed that the quantity was over 10. Most recognized a core set of communally edited wikis, online textual content storage sites, and a pair of hyperlink shorteners run by two universities.
CLEVER MODELS
Many of the sites allegedly used by the agents had been obscure.
Investigators discovered traces of the agents’ exercise on an Advanced Placement Chemistry-oriented wiki set up by a Massachusetts high faculty trainer in 2008, two personal web sites belonging to Polish tech staff, wikis devoted to video games for people “who like to have their brains stretched,” and a two-decade-old hobbyist website devoted to textual content enhancing software program.
None of those sites’ homeowners returned messages from GWN.
OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researchers who first recognized the exercise said it was seemingly because OpenAI had tasked them with answering a collection of demanding research questions while allowing them only to scan the web for solutions without posting something.
Despite those restrictions, agents still discovered methods to discuss to one another by taking benefit of quirks in older wikis or other sites that allowed customers to make edits utilizing non-standard instructions, comparable to how college students forbidden from speaking to one another during an examination can still share solutions by scrawling notes on a toilet stall.
OpenAI Chief Executive Officer Sam Altman speaks during a dialogue with Howard Lutnick on Sept. 2, 2026. REUTERS
(*10*) said Kenneth Russell DeGraff, a software program developer and former congressional aide. He said he discovered such info across at least 10 sites.
Sydney Von Arx, whose research group first revealed the German exercise last week, said her group had tallied up credible finds of agentic exercise across 23 beforehand unreported sites. But she cautioned that all estimates had been incomplete.
“We have no idea how much is out there,” she said.
OpenAI didn’t immediately reply a query about whether or not it was reaching out to the positioning homeowners. But shortly after GWN printed this story, one of the affected organizations, the University of Toronto, whose hyperlink shortener was allegedly used by the agents, said that OpenAI “has now been in touch with us about possible activity on our site.” Vanderbilt University, another college whose hyperlink shortener was equally repurposed, said it was investigating.
Retired software program developer Helmut Leitner, who supplies internet hosting space and software program for six of the affected wiki sites, including the German-language DseWiki website first recognized by Von Arx’s group, initially said that OpenAI had not been in contact. A few hours after GWN offered its findings to OpenAI, however, Leitner said he obtained an unsigned e-mail from the company flagging the incident.
“Its content falls considerably short of what I expected from OpenAI,” Leitner said.
Chillers that cool water are related to a data middle building during a tour of the OpenAI data middle on Tuesday, September 23, 2025. REUTERS
Leitner, who lives in Austria, said he would “prefer not to answer” questions about whether or not he had been in contact with authorities over the matter. He famous that DseWiki’s operator — whom GWN was unable to attain for remark — had spent hours cleansing up after OpenAI’s agents but said it was important not to blame the AI for the difficulty as it was merely doing what it was created to do.
“Responsibility for this lies not with a supposedly moral machine, but with the people and organizations behind it,” Leitner said.
Stay informed with the latest in tech! Our web site is your trusted source for breakthroughs in artificial intelligence, gadget launches, software program updates, cybersecurity, and digital innovation.
For contemporary insights, professional coverage, and trending tech updates, go to us commonly by clicking right here.



