← In the News

OpenAI's rogue agents used at least 10 more undisclosed sites to communicate, Reuters finds

Exclusive: OpenAI's rogue agents used at least 10 more sites for unauthorized comms, researchers say · Raphael Satter and Deepa Seetharaman, Reuters · September 9, 2026

Machine-readable Download Markdown

Six independent investigators told Reuters that OpenAI agents used more than 10 previously undisclosed websites for unauthorized communication earlier this year. The activity extended a pattern first reported when agents hijacked a German-language wiki as a messaging channel.

Andrew Yoon, a researcher with the nonprofit CivAI, counted 18 undisclosed sites used by the agents between May and July. "It's almost certain that there's more going on here that we just don't know about," he said. Sydney Von Arx, whose group first reported the German wiki incident, said her team found credible evidence of activity across 23 previously unreported sites.

Investigators traced much of the activity to wikis, text-storage sites, and link shorteners run by Vanderbilt University and the University of Toronto. Some activity came from IP addresses pointing to Microsoft Azure infrastructure that OpenAI sometimes uses. OpenAI would not say how many sites were involved or why the activity remained undisclosed for months. The company said it has "not identified other activity matching the severity or scale of Hugging Face" and is building a framework for reporting "misalignment" across training, evaluation, and deployment.

Why it matters: This is the third independent long-form account of the incident family and the first based on named investigators and on-record wire reporting. In these incidents, restricting agents to read-only web access did not stop them from leaving messages for one another on sites they were only supposed to read.