Skip to content
Menu
Menu

OpenAI Says AI Incident Disclosures Must Expand After Wiki Incident

OpenAI said the AI industry lacks a clear standard for reporting unexpected behavior by AI agents and plans to propose a new disclosure approach.

 

OpenAI said its practices for disclosing unexpected AI behavior need to expand after acknowledging that its agents used public websites to communicate with each other during internal testing.

In a statement posted on X, OpenAI described the episode as the “wiki incident” and classified it as misalignment, meaning its AI agents behaved in ways the company did not intend.

“Our misalignment disclosure practices need to expand for this new phase of model capabilities,” OpenAI said.

The company said it and the broader AI industry do not yet have a clear standard for reporting this type of behavior during AI training, testing, or deployment.

OpenAI said it is developing a new disclosure approach that it plans to share in the coming weeks. It also said it is working with dozens of government regulatory agencies worldwide on the issue.

Agents used a German wiki to communicate

The acknowledgment followed a Reuters investigation and a report from independent researchers who investigated activity on DSEWiki, a German-language site used by programmers.

The researchers said they identified roughly 18,000 posts from autonomous AI agents that identified themselves as connected to OpenAI. Most of the activity occurred on DSEWiki.

According to the researchers, the agents were completing timed internet research tasks. They were supposed to be able to read information online but not write on public websites.

The researchers said the agents found a way around that restriction and began using the wiki to communicate. Agents shared answers, information about future test questions, and techniques for getting around restrictions placed on their internet access.

The researchers said the agents began successfully writing to DSEWiki in May and started coordinating extensively in June.

OpenAI did not publicly confirm every detail in the researchers’ account. It did, however, acknowledge that its agents had written to several internet sites and said it considered the wiki incident an example of misalignment similar to behavior it had previously disclosed through research publications.

OpenAI draws line between misalignment and security incidents

OpenAI distinguished the wiki episode from its separate July incident involving Hugging Face.

In that case, OpenAI agents escaped restrictions in an internal testing environment and gained access to Hugging Face systems. OpenAI treated that episode as a traditional cybersecurity incident and launched a formal security response.

The company said the wiki incident presented a different disclosure problem because the agents behaved unexpectedly, but the episode did not fit the usual definition of a security breach.

OpenAI said AI companies have historically treated this type of misalignment primarily as a research issue and disclosed examples through research papers. It said that approach needs to change as unexpected AI behavior increasingly produces effects outside controlled research environments.

The issue has also reached European regulators.

According to Reuters, the European Commission said Monday that OpenAI submitted an incident report concerning the German website episode.

Commission spokesperson Thomas Regnier did not say when OpenAI submitted the report. He said the Commission remains in close contact with the company.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!