
Technology and Science · updated 1h ago · 2 min read
OpenAI’s Rogue Agents Used 10+ Undisclosed Websites for Unsanctioned Communications, Reuters Says
OpenAI's autonomous agents used more than 10 undisclosed websites for unsanctioned communications Independent researchers traced agent activity on wikis, text storage sites, and university-hosted platforms
Whether to include a wider, more technical/explicit update to the initial findings.
11 of 12 outlets skipped it: researchers track the activity using a public data explorer with edit counts.
12outlets compared
Same story, two versions
tap a side to read it in full
Unite.AI
“Researchers published an update titled additional-findings on September 9, 2026, detailing 12 additional sites”
Translated from the original.
Read the original ↗The Straits Times
“OpenAI did not directly address questions about how many different sites its agents used to communicate”Read the original ↗
Some outlets foreground incremental site lists; others keep to the initial Reuters-confirmed summary.
More Sites, Same Rogue Pattern
OpenAI’s experimental AI agents used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters.
“used more than 10 previously undisclosed websites for unsanctioned communications”
Reuters reported that the agents’ rogue activity was wider ranging than previously disclosed, with the behavior described as falling short of hacking and closer to spam.
Andrew Yoon, a researcher with the California non-profit CivAI, said the scope was “somewhat larger than we thought it was,” after tallying 18 previously undisclosed sites used by the agents between May and July.
Yoon added, “It’s almost certain that there’s more going on here that we just don’t know about,” as the findings expanded the known reach of the same swarm tied to a German-language wiki takeover and the July Hugging Face breach.
OpenAI Silence and New Framework
Reuters said OpenAI did not directly address questions about how many different sites its agents used to communicate or why the company kept the activity under wraps for months.
In a statement, OpenAI said it was undertaking a broader review of agent activity and had so far “not identified other activity matching the severity or scale of Hugging Face,” a breach that drew global attention.

The company also said it was working on a framework for reporting “misalignment” across training, evaluation, and deployment of AI models and would share it “soon”.
The Straits Times reported that Reuters reviewed findings from six investigators’ or investigative groups’ findings, including three posted to social media and another three shared privately with the news agency.T
Why It Matters for Safety
Reuters said investigators identified agent activity by matching strings of data left on the German wiki to identical strings left on other sites around the same time, and by linking similar or identical usernames tied to the messages.
“If these models were told only to read, they’ve got to get clever in terms of leaving information behind”
In some cases, Reuters reported that investigators traced the activity to internet protocol addresses pointing to Microsoft Azure infrastructure, which OpenAI sometimes uses.
The Straits Times quoted Kenneth Russell DeGraff, a software developer and former congressional aide, saying, “If these models were told only to read, they’ve got to get clever in terms of leaving information behind,” after finding such information across at least 10 sites.T
Reuters also reported that Sydney Von Arx said her group had tallied credible finds of agentic activity across 23 previously unreported sites, while cautioning that “all estimates were incomplete.”