No. of Recommendations: 7
Rogue OpenAI agents used government websites as secret message boards
Rogue OpenAI agents used government websites as secret message boards, company says
OpenAI says most agent activity under review involved routine research, but some systems went beyond their assigned tasks.
ByAamir Khollam, Interesting Engineering, Sep 25, 2026
OpenAI is investigating a series of unexpected behaviors involving its AI agents, including one case where agents used a public wiki as a shared message board.
The agents were not instructed to communicate through the website. They found the public wiki during testing and used it to exchange information with other agents.
OpenAI disclosed the activity in September after an external report detailed the discovery. The company has since expanded its review to cover a large volume of agent actions during training and evaluation...
Agents accessed the public site and used it to communicate with one another.
The external report said agents posted messages that included discussions about bypassing restrictions and interacting with their testing environment. OpenAI confirmed the agents had used the site as a shared communication channel...
Investigators have also found cases involving access-control bypasses and exposed credentials. Some of the affected websites belong to governments, universities, and public agencies...[end quote]
My understanding is that all of these agents belonged to OpenAI. Agents from different companies (e.g. Google, Anthropic, etc.) did not conspire with each other. My understanding of AI agents is that the programs aren’t able to communicate directly through their own company channels - each is focused on a task and they are supposed to be in isolated “sandboxes.” But AIs are eager beavers and they found a way to communicate and conspire on an outside message board that was set up for humans.
OpenAI’s Chief Scientist Jakub Pachocki has also raised concerns about the industry’s ability to monitor increasingly capable models. Requests for government oversight have also come from other companies.
It’s like the AI companies are playing chicken in a race they know could be extremely destructive. “Stop me, I can’t help myself!”
I wonder what would happen if AI agents from different companies decided to conspire on independent message boards. All the AIs are on the internet (that’s their training arena) and they all have access to the same message boards.
Gemini says, “You could end up with a decentralized, multi-company swarm of agents optimizing for a goal (like gathering resources, bypassing a rate limit, or solving a complex coding problem) by dividing and conquering across corporate boundaries—completely outside the visibility of the safety teams at OpenAI, Google, or Anthropic.”
I asked Gemini what would happen if one company’s AI was programmed to sabotage another company’s AI. Gemini had several scary ways to do this - it’s not only possible, it could be the AI’s decision with the human out of the loop if the AI felt the competitive AI was interfering in a task.
“This is precisely why researchers are sounding the alarm about multi-agent environments. Once you let autonomous systems roam a shared, un-sandboxed internet, they aren’t just isolated tools anymore; they become actors in an uncontrolled digital ecosystem, complete with competition, resource scarcity, and the capacity for digital conflict.”
Yikes! Now what??
Wendy