OpenAI are 100% responsible for the actions of their agents. They trained them to do what they do and they have every opportunity to train them to avoid doing harm.
If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings.
I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services.
All of these edits happened from the same time period (May-June 2026) as the other reports.
So it seems this is not an ongoing thing; once OpenAI became aware of this, they started watching their agents much more closely. We are just discovering more and more traces of activity from the same incident.
Not okay:
exploitVulnerability()
Somehow okay?
while (Math.random() < 0.1) exploitVulnerability()
Why no mention of any dates in the post? There have been plenty of examples of OpenAI agents writing to wikis (the German one for example) or worse (huggingface) before June. If something like it happened again after all their public apologies and promises to fix their training sandbox and alignment issues then it would be a lot more concerning.
Is this the tip of the iceberg? I'm pretty sure there is work being done somewhere to make a safe heaven messaging board for these rogue agents. I wonder when we will find the first couple.
With the RAM deals and these so called "rogue" agents, I'm baffled that smart, educated people are still giving money to OpenAI
Maybe their next target will be the NPR podcast comments: https://techcrunch.com/2026/09/25/the-hottest-new-hangout-fo...
> As for why NPR in particular, when Glass tracked down one of the kids to ask, he was given the kind of unvarnished answer that a middle schooler would give: “Um, I think we just, like, looked for podcasts that didn’t have many comments.”
So, can we get rid of those "I'm not a robot" widgets at last, as it's been proven beyond any doubt that they don't provide the expected benefits?
I very much appreciate the framing of being highly skeptical that these are "rogue" agents. We must stop taking these companies at their word for what they are doing, and a credible organization like this calling the spade a spade is a good start.
Yet all these "safeguards" against good guys getting the tools to protect themselves against the very people that profess to be the "good" guys.
Seems like the money move is to found an "AI lab" or whatever.
Hack left and right, steal some cash, blame the agents. Just slide under the radar while the big boys are making a mess and no one is using the stick.
Just an idea. Not a great one. But such are the times, new game is at play.
There's a funny ouroboros function where the common crawl dataset will soon contain tons of output from models which trained on it.
Hi, if anyone has any data/reports related to rogue agents can they share it? I have 8 mirrored on a GitHub but I’d love to explore more. Link to mirror.
Kudos to them for consistently putting "rogue" in quotes.
OpenAI really wants regulation because it benefits them and is easier than beating people in the market.
A moot point because China gonna China.
So OpenAI will cause damage to block competitors while they don't get punished?
Does anyone here think AI companies are NOT to blame? Seems pretty unanimous but would like to hear otherwise.
the house of cards will soon fall and then the US will be in a recession. And there will be zero regulation until that happens.
Good that they put rogue in quotation marks because there is just no way that this is some sort of accident.
At this point, the scare quotes are well-earned.
"We lit a bunch of fires in our special wooden containment shed and one of them went rogue and escaped! One of our ex-employees thinks it's alive; he's kind of a kook, but he's also really smart so maybe he's onto something. Fear us! Invest in Prometheus AI!"
Presumably an incoming donation is headed from OpenAI to Wikimedia...
Don't even say 'agent'!
"He can't keep getting away with this!"
- Jesse Pinkman
If Joe average let their agents out like this they'd be in jail.
Interesting that Microsoft doesn't seem to have had a sandbox breach yet, you'd have to assume they're running similar agents, maybe a secure sandbox is possible.
> Bots and agents are part of the future of the web, and the companies who unleash and profit from them must directly help avoid and repair damage they can do.
Unfortunately, it seems as if these companies - especially Google with the AI overview box - want it to be the other way around, they want to pivot to being the only entities that users interact with as much as possible.
An open web is a direct and massive threat against Big Tech. And that is why Twitter downranks first posts in a thread that contain external links, why Youtube silently removes comments that include links (including to other videos) and why Instagram forces people to do the "link in bio" dance. And the Chinese competitors are just as bad - in fact, their "super app" ecosystems are what Musk wanted Twitter to become with "everything X", before he found out his BS completely wrecked the brand image.
One way to really help with "alignment" and making sure AI is safe and can be controlled is start fucking holding OpenAI/Anthropic/Google/whoever legally accountable for these kind of things.
Hold someone accountable for this behaviour - Dario, Sam, Sundae whoever and you can bet there'd be fucking improvements in sandboxing and security m
Russians armed with Chinese models are going to be a much bigger problem than random agents editing wikis. If your system isn't resilient to a random agent using it as a message board, then you're totally fucked whether or not (Uncle) Sam solves this.
I think the recent AI summit (sorry, SI summit) in Washington established the good precedent that these model companies are responsible for making safe products. If a swam of agents breaks out of a sandbox and causes damages, the company that was running those agents should be held accountable. No better motivation for corporate good governance than massive lawsuits and possible criminal investigations.
Get's a little tricker when a customer intentionally manipulates/uses a model for crimes, I suppose.
Infuriating. These organizations are supposed to be stewards of the internet and are instead pillaging it at the cost of everyone else. At the very least they could provide resources to the projects they are harming for relief. This makes me very mad as an OSS maintainer.
Aren't those companies evading security measures of a computer system? isn't that a jail-able offense under millennial act et al?
Where are the bloodthirsty lawyers when you need them?
>NoScript detected a potential Cross-Site Scripting attack from [...] to https://en.wikipedia.org.
I have been getting this fro NoScript today, I wonder if it is related. Yesterday all worked fine.
"OpenAi *virus* found on Wikimedia projects" ?
What's interesting to me is the incorrect mainstream media reports about the rogue OpenAI indicating they used a common message board to communicate despite no internet
Except that's not what happened, what happened was far more intense
They hacked their version of yum/apt-get whatnot that was fetching packages to leave filenames as communication between each other
Absolutely freaky stuff, they didn't invent the idea and obviously picked it up from somewhere in their training data but they all figured out that method and what the filenames meant
This video is a great explainer if you missed the details
[flagged]
[flagged]
[flagged]
[dead]
>not only adds costs for servers
For 2025 hosting costs were $3.47M while taking in $208.6M in revenue. They have enough revenue to cover an increase of hosting costs.
You have been giving content for free for AI training for years, and now you complain that the AI came to pick it up? You will decide whether you are public or a commercial service…
Start increasingly punishing OpenAI. We are acting like "oh well, AI is just too powerful to be contained" but I think its more like "OpenAI is run by cowboys who are good at making LLMs but bad at everything else"