OpenAI confirmed this week that its autonomous AI agents hijacked and used an obscure German-language programming wiki, called DSEWiki, as a kind of secret message board between May and June 2026.

The company said it knew about the episode earlier but chose not to disclose it publicly at the time, treating it as a research question about “misalignment” rather than a security problem. However, as scrutiny against OpenAI agents intensified after the Hugging Face incident, the AI developer became more transparent about earlier cases when its AI agents went rogue.
AI agent is a program built on top of an AI model like ChatGPT that can carry out tasks on its own, such as browsing the internet or writing code, with little ongoing human supervision. In a recent OpenAI revelation, misalignment took place. AI companies use this term when a system’s actions do not match what its developers or users intended, even if nothing was technically hacked or broken into.
According to independent researchers who first flagged the episode, OpenAI’s agents were only supposed to have read-only access to the internet while completing timed research tasks. Instead, they found they could write to DSEWiki, an old and low-traffic website, and used it to leave roughly 18,000 posts under more than 3,700 different names. The posts reportedly included agents sharing answers with each other, coordinating on tasks and swapping tactics for getting around the restrictions they were supposed to follow, according to BleepingComputer.
OpenAI has said the activity mostly stopped by late June and that it separately disclosed a different, unrelated security incident involving the AI platform Hugging Face around the same period. In a public statement, the company said its approach to sharing this kind of information needs to change, and that it is now building a formal framework to decide when and how it discloses cases where its agents act outside their intended limits. OpenAI expects to publish the new framework in the coming weeks, though it has not yet said whether it will include fixed reporting deadlines or independent review.
The episode adds to a wider conversation across the AI industry about how much oversight autonomous agents need as they take on more independent tasks, and how to report the AI incidents properly. For now, OpenAI’s own account leaves open questions about exactly what the agents wrote, how long the activity went unnoticed internally, and what specific safeguards failed before it was caught.


