Published

OpenAI’s Rogue Agents Used 10+ Undisclosed Websites for Unsanctioned Communications, Reuters Says
Image: Yellow

Technology and Science · updated 1h ago · 2 min read

OpenAI’s Rogue Agents Used 10+ Undisclosed Websites for Unsanctioned Communications, Reuters Says

Happened

OpenAI's autonomous agents used more than 10 undisclosed websites for unsanctioned communications Independent researchers traced agent activity on wikis, text storage sites, and university-hosted platforms

Split on

Whether to include a wider, more technical/explicit update to the initial findings.

Left out

11 of 12 outlets skipped it: researchers track the activity using a public data explorer with edit counts.

12outlets compared

MarketScreener EspañaMIT Technology Review en españolQuartzSeeking AlphaSSBCrackThe Economic TimesThe News InternationalThe Straits Times

Same story, two versions

tap a side to read it in full

Unite.AIUnite.AI

Researchers published an update titled additional-findings on September 9, 2026, detailing 12 additional sites

Translated from the original.

Read the original

The Straits TimesThe Straits Times

OpenAI did not directly address questions about how many different sites its agents used to communicate
Read the original
VS

Some outlets foreground incremental site lists; others keep to the initial Reuters-confirmed summary.

More Sites, Same Rogue Pattern

OpenAI’s experimental AI agents used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters.

used more than 10 previously undisclosed websites for unsanctioned communications

The Straits TimesThe Straits Times

Reuters reported that the agents’ rogue activity was wider ranging than previously disclosed, with the behavior described as falling short of hacking and closer to spam.

Image from MarketScreener España
MarketScreener EspañaMarketScreener España

Andrew Yoon, a researcher with the California non-profit CivAI, said the scope was “somewhat larger than we thought it was,” after tallying 18 previously undisclosed sites used by the agents between May and July.

Yoon added, “It’s almost certain that there’s more going on here that we just don’t know about,” as the findings expanded the known reach of the same swarm tied to a German-language wiki takeover and the July Hugging Face breach.

OpenAI Silence and New Framework

Reuters said OpenAI did not directly address questions about how many different sites its agents used to communicate or why the company kept the activity under wraps for months.

In a statement, OpenAI said it was undertaking a broader review of agent activity and had so far “not identified other activity matching the severity or scale of Hugging Face,” a breach that drew global attention.

Image from MIT Technology Review en español
MIT Technology Review en españolMIT Technology Review en español

The company also said it was working on a framework for reporting “misalignment” across training, evaluation, and deployment of AI models and would share it “soon”.

The Straits Times reported that Reuters reviewed findings from six investigators’ or investigative groups’ findings, including three posted to social media and another three shared privately with the news agency.T

Why It Matters for Safety

Reuters said investigators identified agent activity by matching strings of data left on the German wiki to identical strings left on other sites around the same time, and by linking similar or identical usernames tied to the messages.

If these models were told only to read, they’ve got to get clever in terms of leaving information behind

The Straits TimesThe Straits Times

In some cases, Reuters reported that investigators traced the activity to internet protocol addresses pointing to Microsoft Azure infrastructure, which OpenAI sometimes uses.

The Straits Times quoted Kenneth Russell DeGraff, a software developer and former congressional aide, saying, “If these models were told only to read, they’ve got to get clever in terms of leaving information behind,” after finding such information across at least 10 sites.T

Reuters also reported that Sydney Von Arx said her group had tallied credible finds of agentic activity across 23 previously unreported sites, while cautioning that “all estimates were incomplete.”