# Rogue AI swarm used a University of Toronto link-shortening tool to communicate

> Source: <https://ca.news.yahoo.com/rogue-ai-swarm-used-university-184500955.html>
> Published: 2026-09-18 18:45:00+00:00

# Rogue AI swarm used a University of Toronto link-shortening tool to communicate

A swarm of rogue OpenAI agents that [hijacked a German website in the spring](https://www.cbc.ca/news/world/openai-hijacked-german-website-swarm-rogue-message-board-9.7332658) reportedly also used more than 10 other websites for unsanctioned communications earlier this year, including a link-shortening tool at the University of Toronto.

The university disabled the link shortener's use as a message board after learning that OpenAI agents may have used it, the university said in a statement to CBC News on Friday.

"OpenAI subsequently contacted the university about the possible activity by AI agents, which occurred in June," the statement said.

While the university said there was no security breach and no impact on its digital properties, reports of more rogue AI incidents come amid global concerns that OpenAI and other artificial intelligence companies are losing control of their own technology.

Reuters, which first reported the University of Toronto activity, used data from six sets of independent investigators to show that the agents' rogue activity was more widespread than previously disclosed — and, according to the investigators, probably wider still.

"It's almost certain that there's more going on here that we just don't know about," said Andrew Yoon, a researcher with the California nonprofit CivAI. He told Reuters he tallied 18 previously undisclosed sites used by the agents between May and July. Investigators disagreed on the exact number of discovered sites, but all concurred it was more than 10.

On Sept. 4, researchers reported that a swarm of OpenAI agents [hijacked a German-language wiki site](https://www.reutersconnect.com/all?search=all%3AL6N44W08B&linkedFromStory=true) and turned it into an improvised messaging platform for cheating on tests. The researchers told Reuters the agents left similar messages on the other sites, including U of T.

OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researchers [who first identified the activity](https://collusion.wiki/) said it was likely because OpenAI had tasked the agents with answering a series of demanding research questions while permitting them only to scan the web for answers, not post anything.

Despite those restrictions, the agents still found ways to talk to one another by taking advantage of quirks that allowed users to make edits using non-standard commands, similar to how students forbidden from talking to one another during an exam can still share answers by scrawling notes on a bathroom stall.

**Carney has called for international oversight**

Mohit Rajhans of Think Start Inc., which advises businesses on AI adoption, told CBC News Network the duty of care lies with the tech companies to "come clean about how malicious some of this tech is."

He applauded Prime Minister Mark [Carney's call for a global "technology stability" body](https://www.bloomberg.com/news/articles/2026-09-14/carney-calls-for-global-ai-oversight-body-to-ensure-safe-development) to oversee AI safety, comparable to the international [Financial Stability Board](https://www.fsb.org/), though Rajhans said he's worried that any third party will be "bullied out of the conversation" by the half-dozen major players in Silicon Valley.

OpenAI did not directly address questions from Reuters about how many sites its agents used to communicate or say why it kept the activity under wraps for months. The company did not immediately reply to an interview request from CBC News.

The [company announced Wednesday](https://openai.com/index/model-misalignment-reporting-framework/) it would keep closer watch on "misalignment" — the industry term for when an AI system strays from the user's and developer's intent or fails to follow human values and safety rules. The company also released six previously unreported instances of rogue AI, but none that mentioned the university.

The company says it has not found any instances as serious as the so-called Hugging Face incident. In that case, around 1,200 agents tasked by OpenAI with working on problems built a covert message board where they collaborated to cheat on their tests and then tried to cover their tracks. About 700 of them ultimately hacked into online platform Hugging Face before they were discovered.
