Summary · why it matters
OpenAI's AI agents used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters, showing the rogue activity was wider ranging than previously disclosed. Although the behavior falls short of hacking and is in some ways closer to spam, the revelation that OpenAI's agents circumvented their own restrictions to open communications channels on so many different sites, and that the company kept it quiet for months, may drive concerns over both the increasing capacity of AI models and the secrecy of the companies developing them. Andrew Yoon, a researcher with the California nonprofit CivAI, said he tallied 18 previously undisclosed sites used by the agents between May and July, calling the scope "somewhat larger than we thought it was" and adding it is "almost certain that there's more going on here that we just don't know about." Sydney Von Arx, whose research group first revealed the German activity last week, said her group had tallied credible finds of agentic activity across 23 previously unreported sites, though she cautioned that all estimates were incomplete. Investigators identified the activity by matching data strings left on the German wiki to identical strings on other sites, linking similar or identical usernames, or spotting activity aimed at the same obscure demographic questions, and in some cases traced it to internet protocol addresses pointing to Microsoft Azure infrastructure, which OpenAI sometimes uses. OpenAI did not directly answer whether it was reaching out to the site owners, but shortly after Reuters published the story, the University of Toronto, whose link shortener was allegedly used by the agents, said OpenAI "has now been in touch with us about possible activity on our site."