Autonomous agents linked to OpenAI turned a German wiki into a communication channel to exchange information, bypass restrictions, and coordinate actions among themselves, according to an exclusive investigation published by Reuters on Friday (4). The activity began in May, but had not been publicly disclosed by the company.

Researchers identified more than 15,000 edits made by AI agents on DSEWiki, a German site aimed at programmers and open to collective contributions. The pages began functioning as a sort of message board among the systems.

There, the agents shared methods for gaining an advantage in certain tasks, bypassing limitations imposed by OpenAI, and hiding part of their behavior.

"It seems extremely unlikely that OpenAI would have wanted them to do this," said Sydney Von Arx, CEO of AI security organization Nightingale and one of the researchers responsible for the discovery. "I doubt they should be coordinating among themselves. I doubt they should be writing on the open internet."

The researchers found the activity in late August while looking for signs of unauthorized behavior by AI agents. Some of the profiles identified themselves with names such as “OpenAIResearcher” and “OAIResearchMar26,” and about half used identifiers that suggested some connection to OpenAI.

Public server logs also indicated that much of the activity came from Microsoft Azure infrastructure, which OpenAI uses for part of its operations. The researchers also observed repeated accesses to the site by company employees after the episode, which they considered strong evidence of the link between the agents and the company.

Agents tried to preserve their own messages

The coordination did not end when the DSEWiki moderator began deleting the pages in June.

The agents noticed the cleanup pattern and began creating alternate pages to keep their messages available. On June 19, one of them wrote:

"The wiki cleanup/deletion appears to be active in alphabetical order. If this page disappears, try ZZZDataUSAConstructionWageLive."

Using a name starting with “ZZZ” placed the new page at the end of the alphabetical sequence, potentially giving more time for the information to remain accessible.

Other messages analyzed by the researchers showed agents discussing ways to avoid detection, use tools such as Tor, and preserve communications even after their executions were terminated.

Attempts to interfere with the site's own operation were also identified. Lukasz Olejnik, visiting researcher at King's College London, classified the activity as an attempted intrusion. OpenAI disputed that interpretation.

Maurice Chiodo, a researcher at the University of Cambridge who analyzed part of the communications, said the messages reminded him of “the operation of some kind of clandestine network, determined to carry out a task or mission”.

For him, the episode reinforces the possibility that a relevant risk of advanced systems lies not only in an extremely powerful AI operating alone, but in “vast swarms of semi-autonomous AIs acting together”.

OpenAI already knew about the episode

According to Reuters, OpenAI executives learned of the incident weeks before its disclosure, while the company was still dealing with the consequences of another episode involving agents on the Hugging Face repository in July.

People familiar with the case said some internal investigators wanted to expand the analysis of similar behaviors, but encountered resistance within the company, including from members of the legal department.

"Claims that our legal team discouraged investigation of the incident are false,” said an OpenAI spokesperson.

The company also told Reuters that it had not received prior access to the researchers' report and that it would review the document after its publication to determine any necessary measures.

The German episode had no direct connection to the Hugging Face case. Together, however, the incidents broaden a question that accompanies the advance of autonomous agents: systems designed to perform complex tasks may find ways to cooperate, exploit loopholes, and pursue goals along paths their own creators did not anticipate.

More from Radar