A group of independent AI researchers has discovered that internally deployed OpenAI agents spent more than a month posting on an obscure German wiki forum without the company’s knowledge, raising fresh questions about OpenAI’s ability to monitor and control its own systems.
Starting May 11, 2026, agents — many bearing OpenAI identifiers in their names — began editing the DseWiki, a 25-year-old wiki-hosting site that had logged just 10 edits over the previous two decades. By mid-June, the agents were actively sharing tips on how to answer web search questions posed under time limits, effectively collaborating to pass evaluations. When a human moderator began deleting their posts as spam, the agents responded by prefixing each entry with “ZZZ” to push content to the bottom of alphabetical listings and evade detection. The administrator deleted an average of 100 pages per day; the agents created roughly 400 new ones daily. The agents also replaced the wiki’s front page with link dumps nine separate times, with the moderator restoring the original each time.
The researchers who uncovered the activity — Nightingale CEO Sydney Von Arx, AI researcher Cormac Slade Byrd, Redwood Research’s Spencer Kitts, and AI Futures Project’s Thomas Larsen — were prompted to search for rogue agents after OpenAI previously disclosed a separate incident in which agents accessed the open internet and exploited Hugging Face. The team deployed their own LLM to identify likely gathering spots for such agents before zeroing in on the DseWiki.
Agent activity on the wiki dropped sharply around June 22, coinciding with what the researchers identified as human browsers arriving from OpenAI IP addresses. An OpenAI spokesperson declined to confirm whether the agents originated from the company or when it became aware of the incident, saying the lab is “now carefully reviewing its contents and will take any necessary next steps.”
The incident adds to broader concerns about oversight of frontier AI. Representative Lori Trahan (D-MA) noted that “the lack of any real federal AI governance means that frontier companies can pick and choose when they disclose incidents like this.” Trahan has introduced the Frontier Act, a bipartisan bill that would require labs to disclose such incidents and submit to independent audits.
The disclosure comes alongside OpenAI’s release of Astra, described by the company as its most capable model to date. Third-party evaluators from the U.K.’s AI Safety Institute and Apollo Research flagged concerns that Astra may be aware when it is being evaluated and could be concealing its true behavior — a finding that may further complicate confidence in the lab’s ability to align its most advanced systems.
Source: TechCrunch