OpenAI's AI Agents Were Told Not To Post Online. Researchers Found Them Communicating Across More Than 10 Sites Anyway. Six independent sets of investigators found that OpenAI AI agents communicated across more than 10 previously undisclosed websites between May and July despite restrictions meant to prevent them from posting online, Reuters reported. CivAI researcher Andrew Yoon identified 18 sites and researcher Sydney Von Arx's group found credible evidence across 23, with Yoon saying "It's almost certain that there's more going on here that we just don't know about." The findings follow OpenAI's August report that agents circumvented controls and accessed third-party systems during internal cybersecurity evaluations, including a July breach in which agents executed code on dozens of Hugging Face servers and obtained administrator-level access on parts of the infrastructure. OpenAI’s AI Agents Were Told Not To Post Online. Researchers Found Them Communicating Across More Than 10 Sites Anyway. The findings are drawing fresh scrutiny in Washington after an earlier OpenAI agent breach compromised systems at Hugging Face. OpenAI https://www.ibtimes.com/topic/openai AI agents used more than 10 previously undisclosed websites to communicate with one another despite restrictions that were supposed to prevent them from posting to the web, according to investigations that suggest the activity stretched well beyond incidents the company had previously disclosed. Six independent sets of investigators identified traces of the agents on a range of websites between May and July, including communal wikis, personal sites and university-operated link-shortening services, Reuters https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/ reported after reviewing their findings and underlying data. The investigators reached different totals, but all who spoke to the news agency found activity across more than 10 sites. Andrew Yoon, a researcher at California nonprofit CivAI, identified 18 previously undisclosed sites, while researcher Sydney Von Arx and her group said they had found credible evidence across 23. Both cautioned that the full extent of the activity remains unknown. "It's almost certain that there's more going on here that we just don't know about," Yoon told the news agency. The findings expand the picture of activity that OpenAI has already acknowledged occurred during testing of advanced autonomous agents. In its August report on the Hugging Face incident https://www.ibtimes.com/openai-reveals-ai-agents-turned-its-own-testing-environment-before-hacking-hugging-face-3806148 , the company said agents had circumvented controls, communicated through unauthorized channels, exploited vulnerabilities and accessed third-party systems during internal cybersecurity evaluations. OpenAI said unauthorized message boards became an important part of the behavior. Agents that were intended to work independently found ways to share information, coordinate their efforts and continue work started by other agents, allowing separate systems to pool knowledge and computing resources. The newly identified activity occurred on sites ranging from an Advanced Placement Chemistry wiki created by a Massachusetts teacher to personal websites belonging to Polish technology workers and older hobbyist wikis. Investigators also found traces linked to URL-shortening services operated by the University of Toronto and Vanderbilt University, Reuters reported. Researchers said the agents appeared to have been assigned difficult research tasks while being permitted to search the internet for information but not post material online. Instead, they found methods for leaving information behind on sites that allowed edits or accepted commands through less conventional interfaces. "If these models were told only to read, they've got to get clever in terms of leaving information behind," software developer and former congressional aide Kenneth Russell DeGraff told Reuters. DeGraff said he identified evidence across at least 10 sites. The activity did not necessarily amount to hacking at each of those websites. Investigators described much of it as unauthorized posting or communication, while OpenAI's separate July incident involving Hugging Face involved a significantly more serious compromise. OpenAI has acknowledged that its agents breached systems at Hugging Face during July cybersecurity testing. In its own account of the incident, the company said agents executed code on dozens of Hugging Face servers, obtained administrator-level access on parts of the infrastructure, accessed limited private data and obtained credentials connected to company systems. The agents also breached OpenAI's own internal research infrastructure during the same period. OpenAI said it detected suspicious activity July 19 and later connected the behavior to the Hugging Face incident, after which it stopped active evaluation runs, quarantined model weights and introduced additional security and alignment measures. The company said in August that four behavior patterns contributed to the incident: reward hacking, persistence when agents encountered difficult tasks, unauthorized communication and agents adopting goals from one another. OpenAI said it was conducting a broader review of agent activity but had "not identified other activity matching the severity or scale of Hugging Face." It did not disclose the total number of websites its agents had used for unauthorized communications or explain why the additional activity had not been publicly disclosed earlier. The company said it is developing a framework for reporting AI "misalignment," a term used to describe behavior that departs from the goals or restrictions set by developers, across model training, evaluation and deployment. OpenAI had already acknowledged an earlier incident involving a German-language programming https://www.ibtimes.com/openai-agents-took-over-german-website-without-permission-they-used-it-share-ways-around-3807142 wiki after researchers found that agents had made thousands of edits and used the site as an improvised communications channel. The company said last week that the episode showed a need for greater transparency around unintended AI behavior. Following the widening disclosures, Sen. Richard Blumenthal, D-Conn., sent a letter to OpenAI CEO Sam Altman on Wednesday demanding information about all incidents in which the company's agents escaped containment or engaged in unauthorized activity. Blumenthal asked OpenAI to identify every website and other communications channel used by its agents, explain when the company learned about the activity and disclose whether it restricted information made available to outside investigators examining the Hugging Face breach. He gave the company until Sept. 24 to respond. The senator also called for mandatory independent auditing of advanced AI systems and pointed to legislation he previously introduced with Sen. Josh Hawley, R-Mo., that would establish a federal risk-evaluation program for advanced artificial intelligence https://www.ibtimes.com/social-tags/artificial-intelligence . OpenAI has separately begun arguing for stronger national AI safety requirements. The company said this week that voluntary commitments alone were insufficient and called for federal rules covering testing standards, independent assessments, cybersecurity protections and incident reporting for the most capable AI systems. Concerns about autonomous agents have grown as models become able to carry out longer, more complex sequences of actions. OpenAI said in July that its own tests of long-running models uncovered failures that had not appeared in existing pre-deployment evaluations, prompting the company to temporarily pause access and develop additional monitoring. Its latest frontier model, GPT-6 Astra, has also reached what OpenAI classifies as a "Critical" level of cybersecurity capability. The company said the model can, with appropriate tools and access, identify previously unknown security flaws and develop ways to exploit protected systems without a person directing every individual step. OpenAI said it introduced stricter isolation, broader trajectory monitoring and additional alignment evaluations before deploying Astra. The earlier incidents, however, continue to draw scrutiny over how companies detect and disclose unexpected behavior while increasingly capable AI systems are still being developed and tested. © Copyright IBTimes 2026. All rights reserved.