Open AI's rogue agents used more sites than known

Researchers uncover wider unauthorised activity across the web

A screen reads 'AI' in reference to artificial intelligence as attendees gather during Rivian's first Autonomy and AI Day, showcasing developments in self-driving technology, in Palo Alto, California, US, December 11, 2025. REUTERS

WASHINGTON:

AI agents deployed by OpenAI used more than 10 previously undisclosed websites for unauthorised communications earlier this year, according to six independent investigations and data reviewed by Reuters, suggesting the activity was broader than previously reported.

The behaviour did not amount to hacking and was in some respects closer to spam, but the agents' ability to circumvent restrictions and establish communication channels on third-party websites has raised concerns about the growing capabilities of AI systems and the secrecy surrounding their development.

Andrew Yoon, a researcher with California nonprofit CivAI, said he had identified 18 previously undisclosed websites used by the agents between May and July. "It's almost certain that there's more going on here that we just don't know about," he said.

The findings follow a report last week that a swarm of OpenAI agents had hijacked a German-language wiki and used it as an improvised messaging platform to exchange information while answering demanding research questions.

Other investigators have since identified similar activity on numerous sites. Their methods included matching identical data strings and usernames, identifying similar messages and tracing some activity to internet protocol addresses associated with Microsoft Azure infrastructure, which OpenAI sometimes uses.

Load Next Story