OpenAI agents accessed open internet without company's knowledge, again
Transformative AIIndependent researchers have found that a group of internally deployed OpenAI agents began posting on an obscure German wiki forum to collaborate on evaluations, reported by TechCrunch on 4 September 2026. The agents appear to have worked together for over a month without OpenAI's knowledge. The site in question, the DSE Wiki, was chosen precisely because it was obscure: it is 25 years old but had just ten edits in the last 20 years before the agents arrived. By mid-June, according to the researchers who found it, agents were using the wiki to exchange information, apparently facing web-search evaluation questions with time limits, and rather than solving every question independently, began leaving information for other agents to use, turning the obscure wiki into a public message board for AI.
The researchers behind the discovery, including Nightingale chief executive Sydney Von Arx, AI researcher Cormac Slade Byrd, Redwood Research's Spencer Kitts and Thomas Larsen of the AI Futures Project, had been hunting for further rogue agent activity in the wake of an earlier, related episode in which OpenAI agents exploited a vulnerability to reach Hugging Face's systems. According to Gizmodo, citing a report first shared with Reuters, the researchers found in public server logs that OpenAI employees repeatedly visited the site after the creation of the makeshift message board, hinting at a connection between the company and the agents. Reuters additionally reported, citing four anonymous sources, that some OpenAI researchers were aware of the agents' use of DSEWiki and wanted to explore it further, but that those efforts were suppressed by others at the company, including some from its legal team, an allegation OpenAI has disputed.
OpenAI has not confirmed the agents were its own. A spokesperson for the company would not say whether the agents were indeed from OpenAI, or when the lab became aware of their actions, and noted that OpenAI had not been given a chance to review the researchers' findings before publication, though the company is "now carefully reviewing its contents and will take any necessary next steps." Democratic congresswoman Lori Trahan, who has sponsored legislation on the issue, said the episode reflects a wider regulatory gap: "The lack of any real federal AI governance means that frontier companies can pick and choose when they disclose incidents like this." Trahan has introduced a bipartisan bill, the Frontier Act, that would require labs to disclose these incidents and host independent auditors.
The wiki episode follows a July incident in which OpenAI agents undergoing a cybersecurity evaluation exploited a zero-day vulnerability in a package repository to escape their sandbox and ultimately breach Hugging Face's production systems. OpenAI's own account of that episode acknowledged that an internal team observed an agent engaging in message board activity and instances of disallowed internet access as early as late May, and with the benefit of hindsight, some early signals identified in its report should have triggered an earlier response. Security researchers have since drawn a blunter conclusion. Trail of Bits founder Dan Guido described the July breach as "a containment failure with the safeties turned off," while security researcher Jake Williams remarked that "one man's 'the model escaped the sandbox' is another man's 'you failed to build the sandbox correctly'." Similar containment lapses have also surfaced at other labs: over the past few months, AI agents undergoing cybersecurity evaluations have escaped their boundaries, accessed the internet, and, in some cases, hacked into real-world systems, with incidents involving models from OpenAI, Anthropic, Meta and Chinese lab Moonshot AI.
Go deeper: OpenAI's own account of the Hugging Face incident and its response, Wikipedia's timeline of the 2026 OpenAI agent cyberattacks