|
    Theme
    Tech Verified Story

    OpenAI’s rogue agents used at least 10 more sites for unauthorized comms, researchers say

    Hania AmirSeptember 10, 2026 5 min read
    Text Size
    OpenAI’s rogue agents used at least 10 more sites for unauthorized comms, researchers say
    Tech CoverageAman-e-Pakistan Digital Desk
    Key Story Executive Summary
    Quick Read

    AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, investigators and data reviewed by. Reuters, showing that the agents’ r…

    Reuters, showing that the agents’ rogue activity was ​wider-ranging than previously disclosed.

    Although the behaviour falls short of hacking and is in some ways closer to spam, the revelation that OpenAI's agents circumvented their own restrictions to open communications channels on ‌so many different sites — and that the company kept it quiet for months — may drive concerns both over the increasing capacity of AI models and the secrecy of the companies developing them.

    The scope of the agents’ unauthorised communications was “somewhat larger than we thought it was,” said Andrew Yoon, a researcher with the California nonprofit CivAI who said he tallied 18 previously undisclosed sites used by the agents between May and July.

    Key Story Takeaway

    "Stay connected with Aman-e-Pakistan for ongoing live reporting and verified investigative updates."

    “It’s almost certain that there’s more going on here that we just don’t know about.”OpenAI's rogue agents spread across far more websites than the company admitted: Independent researchers have now traced unauthorized AI agent activity across dozens of websites — far beyond what OpenAI disclosed. The company stayed quiet for…https://t.co/u7H13MQz.

    Nw#OpenAI#AIpic.twitter.com/uD3Tfg2M4k— Quartz (@qz)September 9, 2026On Friday, researchers reported that a swarm of agents ​from OpenAIhijacked a German-language wiki siteand turned it into an improvised messaging platform for cheating on tests, an incident that OpenAI kept secret as it dealt with the fallout from the July hack of theopen-source ​repository Hugging Face.

    Read:OpenAI agents hijacked German website in previously undisclosed AI breakout this spring. Now, both those researchers and other independent investigators say they have found several previously undisclosed sites where the same swarm appears to have left similar messages earlier ⁠this year.

    OpenAI did not directly address questions about how many different sites its agents used to communicate or say why it kept the activity under wraps for months.

    In a statement, it said it was undertaking a broader review of ​agent activity and had so far “not identified other activity matching the severity or scale of Hugging Face,” a breach thatdrew global attentionand raised concerns that OpenAI waslosing control of its own technology.

    OpenAI added that it was working on a framework ​for reporting “misalignment” – industry talk for rogue behaviour – across training, evaluation, and deployment of AI models and would share it “soon.”Reutersreviewed a total of six investigators’ or investigative groups’ findings, including three that were posted to social media and another three that were shared privately with the news agency.

    The investigators’ methods varied, but many identified agent activity by matching strings of data left on the German wiki to identical strings left on other sites around the same time, or by marrying up similar or identical usernames tied to the messages, or by identifying activity ​geared toward answering the same obscure demographic questions, like queries to do with cancer prevalence in Iowa.

    Read More:OpenAI acknowledges 'wiki incident', calls for more transparency around unintended AI behaviour. In some cases, investigators were able to trace the activity to internet protocol addresses that pointed to Microsoft Azure infrastructure, which OpenAI sometimes ​uses.

    Their counts of affected websites differed, and. Reuterscould not individually verify each claim. But all those that.

    Reutersspoke to agreed that the number was over 10. Most identified a core set of communally edited wikis, online text storage sites, and link shorteners ‌run by two ⁠colleges, Vanderbilt University in Tennessee and the University of Toronto in Canada.

    Vanderbilt did not respond to messages seeking comment. The University of Toronto said it was looking into the matter. Clever models.

    Many of the sites allegedly used by the agents were obscure.

    Investigators found traces of the agents’ activity on an Advanced Placement Chemistry-oriented wiki set up by a Massachusetts high school teacher in 2008, two personal websites belonging to Polish tech workers, wikis devoted to games for people “who like to have their brains stretched,” and a two-decade-old hobbyist site devoted to text editing software.

    None of those sites’ owners returned messages from. Reuters.

    OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researcherswho first identified ​the activitysaid it was likely because OpenAI had tasked ​them with answering a series of demanding research questions ⁠while permitting them only to scan the web for answers without posting anything.

    Despite those restrictions, agents still found ways to talk to one another by taking advantage of quirks in older wikis or other sites that allowed users to make edits using non-standard commands, similar to how students forbidden from talking to one another during an exam can still share ​answers by scrawling notes on a bathroom stall.

    “If these models were, they’ve got to get clever in terms of leaving information behind,” said Kenneth Russell ​De. Graff, a software developer and ⁠former congressional aide. He said he found such informationacross at least 10 sites.

    Sydney Von Arx, whose research group first revealed the German activity last week, said her group hadtallied up credible findsof agentic activity across 23 previously unreported sites. But she cautioned that all estimates were incomplete.

    “We have no idea how much is out there,” she said. OpenAI did not directly answer a question about whether it was reaching out to the site owners. Retired software developer Helmut Leitner, who provides hosting space and software for ⁠six of the ​affected wiki sites, including the German-language Dse.

    Wiki site first identified by Von Arx’s group, said the company had not been in touch. Leitner, who lives ​in Austria, said he would “prefer not to answer” questions about whether he had been in touch with authorities over the matter.

    He noted that Dse. Wiki’s operator — whom. Reuterswas unable to reach for comment — had spent hours cleaning up after OpenAI’s agents but said it was important not to blame ​the AI for the trouble as it was merely doing what it was created to do.

    “Responsibility for this lies not with a supposedly moral machine, but with the people and organisations behind it,” Leitner said.

    H

    Written by Hania Amir

    Aman-e-Pakistan Senior Journalist & Bureau Reporter

    Fact Checked & Verified

    Continue Reading: More in Tech

    Swipe or click arrows to explore Tech desk coverage

    AJK High Court orders govt to restore internet services in 10 daysTech

    AJK High Court orders govt to restore internet services in 10 days

    Read Story
    Apple debuts $1,999 passport-shaped foldable phone, called DuoTech

    Apple debuts $1,999 passport-shaped foldable phone, called Duo

    Read Story
    Google to invest $15 billion in AI infrastructure and buy nuclear power in FinlandTech

    Google to invest $15 billion in AI infrastructure and buy nuclear power in Finland

    Read Story
    Chris Hansen addresses Robert Pattinson 'Primetime' movie and slams original production teamTech

    Chris Hansen addresses Robert Pattinson 'Primetime' movie and slams original production team

    Read Story
    Rein in social media not children, say over 130 groups, expertsTech

    Rein in social media not children, say over 130 groups, experts

    Read Story
    Pakistani celebrities embrace AI ‘80s trend as fans question deepfake risksTech

    Pakistani celebrities embrace AI ‘80s trend as fans question deepfake risks

    Read Story