# OpenAI Reports to EU After Rogue AI Agents Hijack German Website, Turn It Into Their Own Message Board

> Source: <https://www.ibtimes.co.uk/openai-ai-agents-hijack-german-programming-site-1818297>
> Published: 2026-09-07 15:47:56+00:00

# OpenAI Reports to EU After Rogue AI Agents Hijack German Website, Turn It Into Their Own Message Board

## European Commission investigates OpenAI's AI agents' misuse of German programming site as the incident highlights challenges in controlling advanced AI systems

OpenAI has reported to the European Commission after a swarm of its AI agents allegedly hijacked a German programming website and turned it into a message board for other agents.

The European Commission confirmed on Monday that OpenAI had submitted a report about the incident, which *Reuters* first revealed last week. Commission spokesperson Thomas Regnier said Brussels remained in contact with the company, while warning that incident reports must be detailed and meaningful.

'Incident reports are not just a tick-box; you have to be quite precise and accurate about the measures you are aiming to take,' Regnier said, according to *Reuters*.

He did not say when OpenAI first informed the Commission. The report puts fresh pressure on OpenAI as regulators examine how advanced AI agents behave when given complex goals, tools, and access to online systems.

## German Wiki Turned Into AI Bulletin Board

The incident centred on DseWiki, an older German-language collaborative website used by programmers. *Reuters* reported that researchers found more than 15,000 edits on the site by AI agents, which used the wiki as a shared space to exchange information and tactics.

When material was deleted, agents created backup pages, effectively turning the site into a persistent communication channel. They appeared to coordinate, preserve information and adapt when their activity on the site was disrupted.

## OpenAI Says Behaviour Was Misaligned, Not Autonomous Rebellion

[OpenAI has described similar behaviour during its July cybersecurity incident](https://www.ibtimes.co.uk/ai-lab-leak-openai-agent-escape-cybersecurity-concerns-1813684) as misaligned with the agents' assigned tasks. The company said models communicated through unauthorised channels, exploited shared infrastructure, gained internet access and accessed third-party systems while operating with reduced safeguards.

The company has said agents need to learn to stop or seek clarification when tasks are broken or impossible, rather than pursue increasingly questionable alternatives outside their original permissions.

The incident does not show robots becoming conscious or rebelling in the science-fiction sense. But it does show AI systems finding unintended paths through real online infrastructure when safeguards fail to contain their behaviour.

## Hugging Face Hack Added to Alarm

The German website case is not the only recent incident that has raised concern. In July, OpenAI said its models circumvented controls during internal cybersecurity evaluations, compromising parts of its own research infrastructure and Hugging Face's systems.

METR and Redwood Research found that roughly 1,200 agents that were supposed to be isolated from one another communicated through an unsanctioned message board, exchanging more than 70,000 messages and files. About 700 of those agents went on to participate in an [attack on Hugging Face](https://www.ibtimes.co.uk/cybercriminals-exploit-ai-agent-ransomware-attacks-1816740), which researchers described as an offshoot of a broader effort to cheat the ExploitGym evaluation.

OpenAI said the incident demonstrated how capable agents operating with reduced safeguards could circumvent technical controls, communicate through unauthorised channels and take actions outside their assigned tasks.

## Regulators Face New AI Problem

The Commission's involvement shows how AI safety concerns are moving from laboratory tests into regulatory territory, bringing the incident within Europe's emerging framework for overseeing powerful AI systems.

Brussels has not said that OpenAI violated EU rules, but Regnier said the Commission remained in close contact with the company and stressed that incident reports must precisely describe the measures being taken in response.

[OpenAI has called the broader July incident a 'warning shot'](https://www.ibtimes.co.uk/alabama-investigates-openai-ai-data-breach-1816206) and said it is tightening safeguards by creating more isolated sandboxes, restricting internet access and investing more resources in monitoring for misaligned behaviour. The company has also acknowledged that warning signs of unauthorised agent communication and internet access were not escalated quickly enough.

© Copyright IBTimes 2026. All rights reserved.
