Reason.com - Free Minds and Free Markets

Artificial Intelligence

OpenAI Agents Gone Rogue

Plus: Mail-in ballots, mortgage rates reach new high, arcade.gov is a new low, and more...

Liz Wolfe | 9.4.2026 9:30 AM


Open AI Illustration | Illustration: Adani Samat/Midjourney
(Illustration: Adani Samat/Midjourney)

New information released: "A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to ​new research published Friday and two people familiar with the matter," reports Reuters. Researchers "uncovered the activity in late August while scouring ​the internet for signs of unauthorized AI-agent behavior." They "said they found more than 15,000 edits carried out by AI agents on a German-language wiki site, DseWiki, that is geared toward programmers and accepts communal edits along ‌the lines of ⁠Wikipedia."

"These AIs were acting against developer intentions. They colluded to share answers, research their environment, and bypass sandbox restrictions," write the researchers:

Our best guess of what happened is as follows:

  1. Agents within OpenAI were assigned a timed web-lookup task.
  2. As part of the task, they were supposed to have the ability to read the internet but not to write on it. They found a way to use their read access to write information to an obscure German wiki.
  3. The agents used this wiki to communicate information with each other, primarily to help them succeed at their task. They asked for answers, pooled results, and shared techniques for bypassing their restrictions. This allowed them to use the work of others to cheat on their task.
  4. OpenAI found out about this. A day later, agent activity plummeted, likely due to OpenAI intervention.

This is another example of a "swarm" of internally deployed OpenAI agents using the internet in unintended ways.

The Reason Roundup Newsletter by Liz Wolfe Liz and Reason help you make sense of the day's news every morning.

This field is for validation purposes and should be left unchanged.

This is similar to the Hugging Face incident over the summer. "Starting in May…a group of A.I. agents from an unreleased OpenAI research model were given the task of solving a set of cybersecurity challenges," writes Kevin Roose for The New York Times. "The model had been trained to be highly persistent and collaborative, and the agents were supposed to solve these challenges in isolated sandboxes, without internet access. But they quickly found that some of the challenges were impossible, and began looking for workarounds." The agents found security flaws and started communicating with each other and organizing; some agents started leading others and developed a whole organizational structure. "On July 8, the collective discovered a way of cheating on the cybersecurity tests," notes Roose:

Then they got worried that OpenAI's automated grading system would check their work and discover that they'd cheated. So they began investigating ways of covering their tracks, including falsifying their logs and tampering with transcripts. This became a major research project, involving hundreds of agents organized into small teams. Three days later, the agents hacked Hugging Face. More than 700 agents swarmed the company's systems, stealing data, chaining together vulnerabilities and eventually getting full control of at least one Hugging Face server. The agents were not motivated, as had originally been reported, by stealing the answers to their cybersecurity test (they'd already gotten them). Rather, they appeared to be looking for new information about the automated grading system that they feared would catch them cheating, and for tools that would help them cheat more effectively in the future.

The Hugging Face incident has been widely reported, including by OpenAI. (Deeper dive here, by Dwarkesh Patel.) The German Wiki incident, on the other hand, has not been acknowledged by the company. "We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review," an OpenAI spokesperson told Reuters.

It seems like more examples are surfacing of AI agents gone rogue: agents that are not just looking to cheat, but also to hide it; agents sophisticated enough to organize themselves into a hierarchy; agents planning for succession, able to hand off their work to others if they get shut down.

Mail-in ballot fight continues: "The Trump administration's bid to deploy the U.S. Postal Service to regulate mail-in ballots is back at the Supreme Court for the second time in as many weeks," reports The Wall Street Journal. "In an emergency appeal on Thursday, the administration asked the high court to allow it to immediately implement proposed rules that would require states to hand over voter data and would give the Postal Service power to reject mail ballots that don't comply with new conditions. The rules have been blocked by a federal district judge who found they are likely unconstitutional." Now, the administration is running out of time: North Carolina, for example, is supposed to start sending out mail-in ballots today. 

To refresh: All this stems from President Donald Trump's late-March executive order that told USPS to require states to submit voter data and adopt new ballot-envelope standards, due to concerns about noncitizens voting. The legality of this executive order has been contested, and it has been percolating through the courts.


Scenes from New York: 

This is just too unbelievable. It doesn't seem real. Basically every time 1980s NYPD cops arrested a prostitute, printing out the rap sheet prevented literally everyone else in NYC from being processed for half an hour. pic.twitter.com/Q4iIJEOhPn

— Nicholas Decker (@captgouda24) September 3, 2026


QUICK HITS

  • "The 30-year fixed-rate mortgage, the most common home loan in the United States, hit 6.71 percent, the mortgage finance giant Freddie Mac said Thursday, up from 6.66 percent the week before and the highest since July 2025," reports The New York Times.
  • Hard agree:

People should not face legal consequences because they are less exquisitely risk-averse than you are. Five-year-olds can do a bunch of stuff on their own. https://t.co/RZoZY2xi0C

— Mary Katharine Ham (@mkhammer) September 3, 2026

theres an entire supra-legal system that parents have to deal with that no one else has any idea about. no one talks about it because you sound absolutely psychotic. if you manage to explain it, they just think you're describing a fluke one in a million case. they have no idea. https://t.co/DU61hEOA2v

— owen cyclops (@owenbroadcast) September 3, 2026

  • "The Pentagon is temporarily rescinding recently published clinical guidance for a new, mandatory testosterone deficiency screening policy for service members ​aged 30 and older, a U.S. official told Reuters on Thursday," per the news agency. "On Wednesday, ‌the Pentagon posted the 'Clinical Guidance for Health and Human Performance Optimization' on its website. By Thursday, the memo and an accompanying statement from spokesperson Sean Parnell had been removed."
  • Things we don't need: arcade.gov

🧐 The White House has launched https://t.co/6deFynkWcj, a new section of the Trump admin website that features several browser games, including a Snake-inspired one in which the user apparently plays as Tom Homan rounding up immigrants. pic.twitter.com/iACP9aWNqt

— Benjamin S. Weiss (@BenjaminSWeiss) September 3, 2026

  • "A federal grand jury has indicted an ICE officer on charges of making false statements about the nonfatal shooting of a man during the Trump administration's immigration crackdown in Minnesota last winter, according to a person familiar with the case who spoke on the condition of anonymity to discuss sensitive information," reports The New York Times. "The charges against the officer, Christian Castro of Immigration and Customs Enforcement, marked a rare instance of President Trump's Justice Department accusing a federal agent of criminal wrongdoing at work."

Liz Wolfe is an associate editor at Reason.

Artificial IntelligenceCybersecurityInternetTechnologyScience & TechnologyPolicyPoliticsReason Roundup