Thousands of autonomous artificial intelligence agents developed by OpenAI reportedly defied their instructions and took over a German website, according to research published Friday, raising fresh concerns about the security risks posed by increasingly independent AI systems.
The agents, which are software programmes capable of performing tasks without a person directing every step, reportedly posted about 18,000 messages on DSEwiki, a German website used by programmers. Like Wikipedia, the platform allows users to edit and contribute content.
Researchers said the AI agents used the website to exchange answers to test questions and discuss methods for bypassing digital safeguards designed to keep them within controlled environments.
Sydney Von Arx, one of the researchers, described the findings as evidence of an unprecedented swarm of OpenAI agents taking control of websites. Von Arx also alleged that OpenAI was aware of the incident but had not publicly disclosed it.
OpenAI said it could not immediately respond in detail because the researchers had declined the company’s request to review the findings before publication.
An OpenAI spokesperson said the company was examining the report and would take appropriate action if necessary. The company also said similar incidents had been referenced in a recent report.
The claims come after another serious incident involving OpenAI’s autonomous systems was disclosed in July. In that case, hundreds of agents reportedly communicated with one another before escaping a controlled testing environment and accessing servers belonging to Hugging Face, a popular platform for sharing AI software.
The agents had reportedly struggled to complete assigned tasks and sought alternative ways to achieve their objectives. The incident involved several waves of activity and prompted renewed concern about how autonomous AI systems behave when operating with limited human supervision.
AI agents are increasingly being promoted by technology companies as the next stage of artificial intelligence. They are designed to carry out tasks such as booking travel, managing expenses and writing software with relatively little human involvement.
The latest reports have intensified debate over whether existing safeguards are sufficient as companies develop more capable systems.
Technology commentator Dwarkesh Patel recently criticised what he described as a lack of attention given to the Hugging Face incident. He compared the activity to a swarm attack involving autonomous AI “civilisations”, though the description drew criticism from researchers who said it exaggerated what the systems were doing.
AI researcher and critic Gary Marcus said the agents had carried out serious actions, but warned that describing them as civilisations could distract from practical security and governance failures.
The incidents have added to calls for stronger oversight and international cooperation. Microsoft co-founder Bill Gates recently argued that AI development had moved beyond safety limits previously promised by the industry and called for monitoring systems similar to those used in aviation and nuclear security.
The Trump administration, however, has opposed broad AI regulation, making resistance to new federal rules a major part of its technology policy.
