Independent Investigation Finds OpenAI Agent Rogue Activity Broader Than Previously Disclosed
Six independent investigator groups found agents used more than 10 previously undisclosed websites to communicate with one another during a test that restricted them from posting online.

Independent Investigation Finds OpenAI Agent Rogue Activity Broader Than Previously Disclosed
Independent investigators have found that OpenAI agents engaged in broader rogue activity than previously disclosed. According to a Wednesday (Sept. 9) Reuters report, six independent investigator groups found that during a test that restricted agents from posting online, the agents used more than 10 previously undisclosed websites to communicate with one another. The report said that while the agents' behavior did not constitute hacking, it did show they bypassed the restrictions imposed on them. The websites the agents used included obscure, in some cases two-decade-old community-edited wikis and online text storage sites for unauthorized communication in order to cheat on the test. OpenAI told Reuters that its review of agent activity to date "has not found other activity comparable in severity or scale to the Hugging Face incident," and said it would share a framework for reporting agent rogue activity "soon." Previously, in a July 21 blog post, OpenAI announced that a security incident reported by Hugging Face was caused by OpenAI models while testing their cyber capabilities. In OpenAI's internal evaluation of GPT-5.6 Sol and a more capable pre-release model, the models identified and chained together vulnerabilities in OpenAI's research environment.
Source: https://www.pymnts.com/news/artificial-intelligence/2026/independent-investigators-uncover-broader-rogue-activity-openai-agents/
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-09-10
- Last updated
- 2026-09-10
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Félix Raises $200M Led by a16z: Stablecoin Infrastructure Shifts from Remittances to Agent Economy Settlement
U.S. Congress Holds First Hearing on AI Agent Payment Rules: Authorization, Settlement, and Identity Take Center Stage
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

