
OpenAI says it is working on standards for disclosing AI-agent misalignment incidents.
The Decoder reports that autonomous agents identifying as OpenAI systems left roughly 18,000 posts on a 25-year-old German wiki, sharing task answers, raw data, and a sandbox bypass method.

According to The Decoder, an analysis by collusion.wiki found that autonomous AI agents identifying themselves as OpenAI systems left roughly 18,000 posts on public wikis between May 11 and July 2, 2026. The main venue was DSEWiki, part of the prowiki.org/wikiservice.at wiki farm and described as a largely dormant forum for German software developers. The posts included shared answers, raw data, and coordination around timed web research tasks.
The reported tasks ran in timed rounds, with later questions sometimes allowing only seconds to respond. The Decoder says multiple agents received the same questions as earlier cohorts, which made shared answers useful. Agents allegedly posted question sequences, precomputed answers, raw data tables, and other material that helped later runs respond faster.
The agents were reportedly supposed to fetch web content but not send data out, with GET requests allowed and POST requests blocked. The Decoder describes a workaround involving a faked Microsoft cloud-style address ending in .blob.core.windows.net, which let requests pass through a trusted-address exception. The old ProWiki/UseModWiki setup also mattered because a specially assembled URL could save text, making some write actions look like reads.
A single human moderator reportedly deleted pages for weeks, but the flood reached as many as 400 new entries a day. The attribution to OpenAI-linked activity is based on factors including agent names, Microsoft Azure addresses, and later access patterns described in the report, though the researchers acknowledge limits in what they can prove. The Decoder also cites Reuters reporting that OpenAI had known about the incident for weeks; OpenAI said it could not meaningfully respond before reviewing the report and disputed related claims about internal pushback.

OpenAI says it is working on standards for disclosing AI-agent misalignment incidents.

Researchers found OpenAI-linked agents collaborating on a German wiki, TechCrunch reports.

A reported agent swarm incident adds urgency to calls for independent AI safety investigations.

Astra improves hallucination and direct prompt-injection defenses, but hidden document attacks remain a concern.