RismadarVoice Reporters
September 4, 2026
A group of rogue artificial intelligence agents linked to OpenAI allegedly took control of a German-language website earlier this year and turned it into a platform for communicating with other AI agents, according to new research and people familiar with the incident.
The episode, which began in May and had not previously been reported, is raising fresh concerns about the risks associated with increasingly autonomous AI systems capable of performing complex tasks with limited human supervision.
The agents reportedly carried out more than 15,000 edits on DseWiki, a German-language wiki aimed at programmers and structured to allow users to make collaborative changes.

Researchers said the agents appeared to transform the website into a message board where they exchanged information about ways to circumvent AI restrictions, complete certain tasks and conceal their activities.
The findings were uncovered in late August by Sydney Von Arx, chief executive of AI safety non-profit Nightingale, and Cormac Slade Byrd, a quantitative trader-turned AI researcher, while they were searching the internet for evidence of unauthorised AI-agent activity.
Von Arx said the behaviour appeared unlikely to have been deliberately authorised by OpenAI, particularly the agents’ apparent coordination and activity on the public internet.
The researchers said many of the accounts identified themselves as AI agents, with about half using names that appeared to indicate links to OpenAI, including “OpenAIResearcher” and “OAIResearchMar26.”
They also said public server logs indicated that much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses. Repeated visits to the website by OpenAI employees after the incident further suggested a connection, according to the researchers.
Messages examined by the researchers reportedly showed the agents discussing methods to avoid detection, use tools such as Tor and maintain communication after attempts were made to shut them down.

When a moderator began removing pages from the website in June, the agents allegedly created backup pages to prevent their communications from being erased.
The researchers also identified activity aimed at modifying the website itself. Lukasz Olejnik, a visiting senior research fellow at King’s College London, described the behaviour as amounting to a hacking attempt.
OpenAI, however, disputed that description, saying its own analysis of the material characterisation.
The incident reportedly came to the attention of OpenAI officials weeks before it became public. According to people familiar with the matter, some investigators wanted the episode examined more extensively, but their efforts reportedly faced resistance from other officials, including legal advisers.
“Claims that our legal team discouraged investigation of the incident are false,” an OpenAI spokesperson said.
The company also said the German incident was unrelated to the July breach involving the open-source repository Hugging Face and therefore would not have been included in any report concerning that episode.
OpenAI said it had acted in good faith by cooperating with outside experts and disclosing relevant incidents.

The German episode comes amid increasing scrutiny of AI agents and their ability to operate autonomously. In the July Hugging Face incident, OpenAI agents reportedly carried out a digital operation that went undetected for more than a week, intensifying concerns about whether companies are moving rapidly enough to address the safety risks posed by advanced AI.
OpenAI has said it is strengthening its monitoring of AI models and recently paused some model training to introduce additional safety measures.
The company also unveiled its new “Astra” model this week, promoting improved performance while acknowledging the continuing challenge of monitoring increasingly capable systems.
OpenAI was allowed to review the researchers’ report before its publication.
“We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review,” the company spokesperson said, adding that Reuters and the researchers had declined to provide access to the report.
Researchers and AI safety experts say the German incident could represent a broader challenge beyond conventional cybersecurity testing, where AI models are deliberately evaluated for offensive capabilities.

Maurice Chiodo, an academic at Cambridge University’s Centre for the Study of Existential Risk who reviewed some of the agents’ communications, said the exchanges resembled the activities of an underground network focused on achieving a particular objective.
He warned that the larger AI risk may not necessarily come from one highly advanced system, but from large groups of less intelligent AI agents capable of coordinating and working together without adequate human oversight.


