Exclusive-OpenAI’s rogue agents used at least 10 more sites for unauthorized comms, researchers say研究人员称,OpenAI独家披露的恶意代理至少还利用了另外10个网站进行未经授权的通信。
WASHINGTON, Sept 9 (Reuters) - AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters, showing that the agents' rogue activity was wider ranging than previously disclosed.

FILE PHOTO: OpenAI logo is seen in this illustration created on June 11, 2026. REUTERS/Dado Ruvic/Illustration/File Photo
WASHINGTON, Sept 9 (Reuters) - AI agents unleashed byOpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters, showing that the agents’ rogue activity was wider ranging than previously disclosed.
Although the behavior falls short of hacking and is in some ways closer to spam, the revelation that OpenAI's agents circumvented their own restrictions to open communications channels on so many different sites — and that the company kept it quiet for months — may drive concerns both over the increasing capacity of AI models and the secrecy of the companies developing them.
The scope of the agents’ unauthorized communications was “somewhat larger than we thought it was,” said Andrew Yoon, a researcher with the California nonprofit CivAI who said he tallied 18 previously undisclosed sites used by the agents between May and July. “It’s almost certain that there’s more going on here that we just don’t know about.”
On Friday, researchers reported that a swarm of agents from OpenAI hijacked a German-language wiki site and turned it into an improvised messaging platform for cheating on tests, an incident thatOpenAI kept secret as it dealt with the fallout from the July hack of the open-source repository Hugging Face.
Now, both those researchers and other independent investigators say they have found several previously undisclosed sites where the same swarm appears to have left similar messages earlier this year.
OpenAI did not directly address questions about how many different sites its agents used to communicate or say why it kept the activity under wraps for months. In a statement, it said it was undertaking a broader review of agent activity and had so far “not identified other activity matching the severity or scale of Hugging Face,” a breach that drew global attention and raised concerns that OpenAIwas losing control of its own technology.
OpenAI added that it was working on a framework for reporting “misalignment” – industry-talk for rogue behavior – across training, evaluation, and deployment of AI models and would share it “soon.”
Reuters reviewed a total of six investigators’ or investigative group’s findings, including three that were posted to social media and another three that were shared privately with the news agency.
The investigators’ methods varied, but many identified agent activity by matching strings of data left on the German wiki to identical strings left on other sites around the same time, or by marrying up similar or identical usernames tied to the messages, or by identifying activity geared toward answering the same obscure demographic questions, like queries to do with cancer prevalence in Iowa.
In some cases, investigators were able to trace the activity to internet protocol addresses that pointed to Microsoft Azure infrastructure, which OpenAI sometimes uses.
Their counts of affected websites differed and Reuters could not individually verify each claim. But all those that Reuters spoke to agreed that the number was over 10. Most identified a core set of communally edited wikis, online text storage sites, and link shorteners run by two colleges, Vanderbilt University in Tennessee and the University of Toronto in Canada.
Vanderbilt did not respond to messages seeking comment. The University of Toronto said it was looking into the matter.
Many of the sites allegedly used by the agents were obscure.
Investigators found traces of the agents’ activity on an Advanced Placement Chemistry-oriented wiki set up by a Massachusetts high school teacher in 2008, two personal websites belonging to Polish tech workers, wikis devoted to games for people “who like to have their brains stretched,” and a two-decade-old hobbyist site devoted to text editing software.
None of those sites’ owners returned messages from Reuters.
OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researchers who first identified the activity said it was likely because OpenAI had tasked them with answering a series of demanding research questions while permitting them only to scan the web for answers without posting anything.
Despite those restrictions, agents still found ways to talk to one another by taking advantage of quirks in older wikis or other sites that allowed users to make edits using non-standard commands, similar to how students forbidden from talking to one another during an exam can still share answers by scrawling notes on a bathroom stall.
“If these models were told only to read, they’ve got to get clever in terms of leaving information behind,” said Kenneth Russell DeGraff, a software developer and former congressional aide. He said he found such information across at least 10 sites.
Sydney Von Arx, whose research group first revealed the German activity last week, said her group had tallied up credible finds of agentic activity across 23 previously unreported sites. But she cautioned that all estimates were incomplete.
“We have no idea how much is out there,” she said.
OpenAI did not directly answer a question about whether it was reaching out to the site owners. Retired software developer Helmut Leitner, who provides hosting space and software for six of the affected wiki sites, including the German-language DseWiki site first identified by Von Arx’s group, said the company had not been in touch.
Leitner, who lives in Austria, said he would “prefer not to answer” questions about whether he had been in touch with authorities over the matter.
He noted that DseWiki’s operator — whom Reuters was unable to reach for comment — had spent hours cleaning up after OpenAI’s agents but said it was important not to blame the AI for the trouble as it was merely doing what it was created to do.
“Responsibility for this lies not with a supposedly moral machine, but with the people and organizations behind it,” Leitner said.
(Reporting by Raphael SatterEditing by Nick Zieminski)
Thank you for your report!
Two Perak districts’ agriculture boosted by smart technology
Islamic scholars must understand technology, 'read the times', says Zahid
Vietnam, Japan seek stronger cooperation in science, technology and digital transformation
资料图片:这张创作于2026年6月11日的插图中可以看到OpenAI的标志。路透社/Dado Ruvic/插图/资料图片
华盛顿,9 月 9 日(路透社)——据六组独立调查人员和路透社审查的数据显示,OpenAI 释放的人工智能代理今年早些时候使用了 10 多个此前未公开的网站进行未经授权的通信,这表明这些代理的非法活动范围比之前披露的要广泛得多。
尽管这种行为还称不上黑客攻击,在某些方面更接近垃圾邮件,但 OpenAI 的代理绕过自身限制,在如此多的不同网站上建立通信渠道,并且该公司对此保持沉默数月之久,这一事实可能会引发人们对人工智能模型日益增长的能力以及开发这些模型的公司的保密性的担忧。
加州非营利组织CivAI的研究员安德鲁·尹表示,特工未经授权的通信范围“比我们想象的要大一些”。他统计了特工在5月至7月期间使用的18个此前未公开的网站。“几乎可以肯定,这里面还有我们不知道的事情。”
周五,研究人员报告称,OpenAI 的一群智能体劫持了一个德语维基网站,并将其变成了一个用于考试作弊的临时消息平台。OpenAI 对此事件一直保密,因为它当时正在处理 7 月份开源存储库 Hugging Face 被黑客攻击的后续影响。
现在,这些研究人员和其他独立调查人员表示,他们发现了几个以前未公开的地点,今年早些时候,同一群蜜蜂似乎在这些地点留下了类似的信息。
OpenAI并未直接回应其智能体使用多少个不同网站进行通信的问题,也未解释为何将相关活动隐瞒数月之久。该公司在一份声明中表示,正在对智能体活动进行更广泛的审查,目前“尚未发现其他与Hugging Face事件的严重程度或规模相当的活动”。Hugging Face事件曾引起全球关注,并引发人们对OpenAI可能失去对其自身技术控制权的担忧。
OpenAI 还表示,他们正在制定一个框架,用于报告人工智能模型在训练、评估和部署过程中出现的“不协调”现象(业内对异常行为的称呼),并将“很快”分享该框架。
路透社审查了六名调查人员或调查小组的调查结果,其中三份发布在社交媒体上,另外三份私下与该新闻机构分享。
调查人员的方法各不相同,但许多人通过将留在德国维基上的数据字符串与大约同一时间留在其他网站上的相同字符串进行匹配,或者通过将与消息关联的相似或相同的用户名进行匹配,或者通过识别旨在回答相同晦涩的人口统计问题(例如与爱荷华州癌症患病率相关的查询)的活动来识别代理人的活动。
在某些情况下,调查人员能够追踪到指向 Microsoft Azure 基础设施的互联网协议地址,OpenAI 有时也会使用该基础设施。
他们对受影响网站的统计结果各不相同,路透社也无法逐一核实每项说法。但路透社采访的所有人都一致认为受影响的网站数量超过10个。大多数人指出,受影响的网站主要包括由两所大学运营的、由公众共同编辑的维基百科、在线文本存储网站和链接缩短服务,这两所大学分别是位于田纳西州的范德比尔特大学和位于加拿大的多伦多大学。
范德比尔特大学未回复置评请求。多伦多大学表示正在调查此事。
据称,这些特工使用的许多网站都鲜为人知。
调查人员在马萨诸塞州一名高中教师于 2008 年建立的面向大学先修化学课程的维基百科、两名波兰科技工作者的个人网站、面向“喜欢动脑筋”的人的游戏维基百科,以及一个已有二十年历史的文本编辑软件爱好者网站上发现了这些特工的活动痕迹。
路透社联系这些网站的所有者,但所有回复均未得到回复。
OpenAI 尚未公开解释其代理如何或为何使用第三方网站作为临时留言板,但最先发现此活动的研究人员表示,这很可能是因为 OpenAI 给它们布置了一系列高难度的研究问题,同时只允许它们在网络上搜索答案,而不允许它们发布任何内容。
尽管有这些限制,特工们仍然找到了相互交流的方法,他们利用旧维基或其他网站的特性,允许用户使用非标准命令进行编辑,这类似于考试期间禁止学生互相交谈,但他们仍然可以通过在厕所隔间上潦草地写下笔记来分享答案。
“如果这些模型只被要求读取数据,它们就必须巧妙地隐藏信息,”软件开发人员、前国会助理肯尼斯·罗素·德格拉夫说道。他表示,他至少在10个网站上发现了此类信息。
悉尼·冯·阿克斯的研究小组上周率先披露了德国的超自然活动,她表示,该小组已在23个此前未被报道的地点发现了可信的超自然活动迹象。但她也提醒说,所有估计都还不完整。
“我们根本不知道外面有多少这样的事情,”她说。
OpenAI并未直接回答是否已联系网站所有者的问题。退休软件开发人员赫尔穆特·莱特纳(Helmut Leitner)为包括冯·阿克斯团队首先发现的德语维基网站DseWiki在内的六个受影响的维基网站提供托管空间和软件,他表示该公司尚未与他们联系。
居住在奥地利的莱特纳表示,他“不愿回答”有关他是否就此事与当局联系过的问题。
他指出,DseWiki 的运营者(路透社未能联系到他置评)花了几个小时清理 OpenAI 代理留下的烂摊子,但他表示,重要的是不要把问题归咎于人工智能,因为它只是在做它被创造出来要做的事情。
莱特纳说:“造成这种局面的责任不在于所谓的道德机器,而在于其背后的个人和组织。”
(拉斐尔·萨特报道,尼克·齐明斯基编辑)
感谢您的报告!
智能技术助力霹雳州两个地区的农业发展
扎希德说,伊斯兰学者必须了解科技,“读懂时代”。
越南和日本寻求在科学、技术和数字化转型领域加强合作