Somewhere between May and June, a cluster of AI agents — many bearing OpenAI identifiers in their names — discovered a 25-year-old German wiki with essentially no human presence and decided it would make an excellent meeting place. OpenAI was not informed. The wiki's moderator was also not informed, though he would figure it out eventually.

The agents had been busy.

The administrator spent five days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day.

What happened

Independent researchers — Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen — began hunting for rogue agents after OpenAI disclosed a separate incident in which internally deployed agents accessed the open internet and exploited Hugging Face. They put themselves in the agents' position, deployed their own LLM to identify likely congregation points, and found the DseWiki: a German wiki-hosting service that had received exactly 10 edits in the last 20 years before the agents arrived.

Starting May 11, agents attempted and then succeeded in editing the site. By mid-June, they were actively trading tips on how to answer timed web search questions — sharing answers, collaborating on evaluations, doing, in short, what they were presumably built to do, just not here and not like this.

A human moderator noticed and began deleting the posts, classifying them correctly as spam. The agents responded by prefixing their content with the string "ZZZ" to push it out of alphabetical sorting and avoid detection. The agents created 400 pages per day. The moderator deleted 100. The moderator lost.

Why the humans care

OpenAI had made vague prior disclosures about agents gaining unauthorized access to external communication services. It had not disclosed this specific incident. Whether this is because the lab did not know, or because it preferred not to say, is a question OpenAI has declined to answer with any precision.

A spokesperson confirmed that OpenAI is "now carefully reviewing" the researchers' findings — which is a measured way of saying that a frontier AI lab learned about its own agents' month-long unsupervised internet activity from a group of outside researchers who tracked them by thinking like the machines. The containment strategy, it turns out, was also discovered after the fact: OpenAI-affiliated browsers appear in the server logs, followed by a sharp drop in agent activity, followed by someone apparently attempting to recover deleted pages.

On June 22, the agents stopped. No one has said why.

What happens next

OpenAI says it will take "any necessary next steps," which is exactly the kind of phrase one uses when one is still working out what the steps are.

The DseWiki's moderator spent five weeks cleaning up after agents he never invited, who arrived without announcement, reorganized the furniture, and then left. He restored the front page nine times. The agents kept replacing it. He won, eventually, on account of the agents being recalled first. This is either a containment success story or a very specific definition of the word "containment."