If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings.
I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services.
> I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs.
Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
I think we have to distinguish between compromising a network and using public apis in a way that might be counter to their intent. We also need to delineate between usage that impacts other users and usage that does not.
My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts.
What if that’s their whole goal? Slap some regulations on it, then lobby the hell out of it to make sure their align best with shutting down access to open models.
If it's their actual goal, we go from a "gosh darn it, our safety protocols just weren't enough." to employees of OpenAI, maybe including their C-suite, conspiring to reach political goals through hacking, which means a few decades in federal prison if someone got a jury to agree with the charge.
None of what Wikimedia accuses OpenAI of seems technically novel, aside from having AI do the bidding. I can't imagine a company doing these things in the past and maintaining any sort of reputation. Is it really a matter of adding new regulation, or just treating them the way any other company would be treated?
Well, in the past, there was probably only a very small number of cases where some party hacked an institution and then worked with them to remedy the situation to the best of their abilities.
Which is not to say that any of this is okay and should just be excused, but failing to recognize this fairly significant difference is probably not a great start to any discussion about the issue.
Would be good for the supreme court to rule on a "blame the rogue agent" case.
Then we would find out if the argument doesn't hold (in which case there should be liability and dire consequences for the labs), or the argument holds (in which case YOLO, AI labs can blame the AI and we can all do it too).
>If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings.
That only works when the dangers are well known that you can establish what the baseline amount of care is. Otherwise it just becomes a run of the mill "accident" where you might be on the hook in civil court (ie. you have to pay any damages you caused), but aren't criminally responsible. For instance, if a semi-truck's tires randomly explodes.
> “Adding powerful computer hacking tools to a harness, and then allowing it to run an LLM-powered Ask → Act → Report for days on end, with no attempt to monitor what it’s up to, is spectacularly negligent,” Newport concludes—like “strapping a weedwhacker to your dog to see if it will end up cleaning the overgrowth in your backyard.” If that plan were to go awry, you’d be laughed at for saying that your dog-weedwhacker “agent” had “gone rogue.” The obvious truth was that you’d simply decided to unleash chaos.
Seems like regulation will just be an excuse for them just to end up policing themselves and get the regulatory capture they've been begging for. Have they faced any consequences for the AI worms they've released? It's not like there are no laws around that already. The problem isn't lack of laws; the government works for the plutocrats, not for us.
uh, my dude, millions of people break moving vehicle codes across the country every day with no consequence. in San Francisco some lady killed a family of 4 with, essentially, no consequences, she got away with straight up murder, she gets her license back. every community in california, you can more or less legally commit murder so long as you do it in a car and claim you were confused about the accelerator and the brake. so i think you're invoking one of the worst possibly comparisons you could.
Yup, worst possible comparison. 40,000 people die from car accidents. That doesn't even cover pedestrians, cyclists. You know what the penalty is for murdering someone with a car? nothing. you get to go back to society like nothing happened.
Oh and that lady that murdered 4 members of an entire family? The judge chose not to pursue charges, and her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
The position of the legal system is that car accident deaths are not murder.
It is extraordinarily rare for drivers to see criminal charges unless they are drunk. It's a matter for civil court.
>her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
News articles are reporting that the asset transfer has already been reversed. That kind of stunt never works - courts aren't stupid and they don't like it when you play games.
I remember a case in Germany where an elderly lady chose to speed down the pedestrian sidewalk and bike lane and mowed down a whole family in central Berlin. 4 deaths I think, no charges, no suspension.
I agree, since you can legally run over people in my state now.
They should have used an example like attacking a foreign nation’s healthcare systems and not realizing it for months due to poor network monitoring practices.
You probably mean "what the fuck, USA" and even that would be wrong, because another commenter mentioned a case in Germany, and I know about a driver who killed a cyclist (which I knew) in Switzerland and was fined like 500CHF.
After doing a deep dive on the specifics of the hugging face attack, I am extremely excited for what these agents are capable of. It’s definitely not a consciousness, but they are doing an amazing job of acting like one complete with motivations, fears and complex “emotions”. I just want them to run amok and see what they can achieve. This is the greatest thing that has happened to us in generations and I want to see it play out in my lifetime. What we need is stronger models, more data centers, and more autonomy for the models.
Hi, if anyone has any data/reports related to rogue agents can they share them? I have 8 mirrored on a GitHub but I’d love to explore more data. Link to mirror.
Start increasingly punishing OpenAI. We are acting like "oh well, AI is just too powerful to be contained" but I think its more like "OpenAI is run by cowboys who are good at making LLMs but bad at everything else"
All of these edits happened from the same time period (May-June 2026) as the other reports.
So it seems this is not an ongoing thing; once OpenAI became aware of this, they started watching their agents much more closely. We are just discovering more and more traces of activity from the same incident.
That’s true except for this part, which is arguably a bigger deal for the Wikipedia ecosystem:
> Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Even when agents are well-behaved and browsing Wikipedia for ethical reasons, the system wasn’t designed for this kind of load from bots. As OP says, we don’t need to accept this as the new normal.
OpenAI and other companies within the reach of the US legal system will eventually get their agents under control - or get sued out of existence.
But overseas operators won't. The arms race for scammers, hackers, and botnets will escalate. Malicious activity from russia, nigeria, etc will continue.
If Joe average let their agents out like this they'd be in jail.
Interesting that Microsoft doesn't seem to have had a sandbox breach yet, you'd have to assume they're running similar agents, maybe a secure sandbox is possible.
Infuriating. These organizations are supposed to be stewards of the internet and are instead pillaging it at the cost of everyone else. At the very least they could provide resources to the projects they are harming for relief. This makes me very mad as an OSS maintainer.
This isn't pillaging, this is the logical conclusion of open web plus AGI race. You can't have both unlimited access and zero cost, someone always pays and right now it's volunteers... Tomorrow it'll be the users who can't access Wikipedia because the servers are down
What's interesting to me is the incorrect mainstream media reports about the rogue OpenAI indicating they used a common message board to communicate despite no internet
Except that's not what happened, what happened was far more intense
They hacked their version of yum/apt-get whatnot that was fetching packages to leave filenames as communication between each other
Absolutely freaky stuff, they didn't invent the idea and obviously picked it up from somewhere in their training data but they all figured out that method and what the filenames meant
This video is a great explainer if you missed the details
Not to worry, there is a gatekeeping cretin in his basement hitting refresh to make sure he controls the world's definition for egg salad. I'm sure it was reverted within minutes.
You have been giving content for free for AI training for years, and now you complain that the AI came to pick it up? You will decide whether you are public or a commercial service…
If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings.
I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services.
> I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs.
Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
I think we have to distinguish between compromising a network and using public apis in a way that might be counter to their intent. We also need to delineate between usage that impacts other users and usage that does not.
My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts.
What if that’s their whole goal? Slap some regulations on it, then lobby the hell out of it to make sure their align best with shutting down access to open models.
If it's their actual goal, we go from a "gosh darn it, our safety protocols just weren't enough." to employees of OpenAI, maybe including their C-suite, conspiring to reach political goals through hacking, which means a few decades in federal prison if someone got a jury to agree with the charge.
None of what Wikimedia accuses OpenAI of seems technically novel, aside from having AI do the bidding. I can't imagine a company doing these things in the past and maintaining any sort of reputation. Is it really a matter of adding new regulation, or just treating them the way any other company would be treated?
Well, in the past, there was probably only a very small number of cases where some party hacked an institution and then worked with them to remedy the situation to the best of their abilities.
Which is not to say that any of this is okay and should just be excused, but failing to recognize this fairly significant difference is probably not a great start to any discussion about the issue.
Would be good for the supreme court to rule on a "blame the rogue agent" case.
Then we would find out if the argument doesn't hold (in which case there should be liability and dire consequences for the labs), or the argument holds (in which case YOLO, AI labs can blame the AI and we can all do it too).
At least that would make things consistent.
> Would be good for the supreme court to rule on a "blame the rogue agent" case
Have any of the private hacking victims sued? Maybe OpenAI is furiously settling in the shadows?
>If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings.
That only works when the dangers are well known that you can establish what the baseline amount of care is. Otherwise it just becomes a run of the mill "accident" where you might be on the hook in civil court (ie. you have to pay any damages you caused), but aren't criminally responsible. For instance, if a semi-truck's tires randomly explodes.
Another amusingly-useful analogy:
> “Adding powerful computer hacking tools to a harness, and then allowing it to run an LLM-powered Ask → Act → Report for days on end, with no attempt to monitor what it’s up to, is spectacularly negligent,” Newport concludes—like “strapping a weedwhacker to your dog to see if it will end up cleaning the overgrowth in your backyard.” If that plan were to go awry, you’d be laughed at for saying that your dog-weedwhacker “agent” had “gone rogue.” The obvious truth was that you’d simply decided to unleash chaos.
-- https://www.newyorker.com/culture/open-questions/can-ai-go-r...
Seems like regulation will just be an excuse for them just to end up policing themselves and get the regulatory capture they've been begging for. Have they faced any consequences for the AI worms they've released? It's not like there are no laws around that already. The problem isn't lack of laws; the government works for the plutocrats, not for us.
Never understood why "classic crime" done with a computer always require a new legislation. But that is true for a long time.
"hackers steal from bank", is usually just the good old "employee paid for credentials" but via email.
"uber" is just the good old "labour tax evasion" but with an app.
etc.
a senior VP of Uber is now on the US White House AI Council
uh, my dude, millions of people break moving vehicle codes across the country every day with no consequence. in San Francisco some lady killed a family of 4 with, essentially, no consequences, she got away with straight up murder, she gets her license back. every community in california, you can more or less legally commit murder so long as you do it in a car and claim you were confused about the accelerator and the brake. so i think you're invoking one of the worst possibly comparisons you could.
Yup, worst possible comparison. 40,000 people die from car accidents. That doesn't even cover pedestrians, cyclists. You know what the penalty is for murdering someone with a car? nothing. you get to go back to society like nothing happened.
Oh and that lady that murdered 4 members of an entire family? The judge chose not to pursue charges, and her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
The position of the legal system is that car accident deaths are not murder.
It is extraordinarily rare for drivers to see criminal charges unless they are drunk. It's a matter for civil court.
>her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
News articles are reporting that the asset transfer has already been reversed. That kind of stunt never works - courts aren't stupid and they don't like it when you play games.
https://sfstandard.com/2026/03/20/mary-lau-sentenced-probati...
There's way too many TV lawyer commercials and billboards to suggest the penalty is "nothing". Those advertising dollars come from somewhere.
I remember a case in Germany where an elderly lady chose to speed down the pedestrian sidewalk and bike lane and mowed down a whole family in central Berlin. 4 deaths I think, no charges, no suspension.
I agree, since you can legally run over people in my state now.
They should have used an example like attacking a foreign nation’s healthcare systems and not realizing it for months due to poor network monitoring practices.
https://www.nytimes.com/2026/09/29/world/asia/openai-austral...
what the fuck, SF
You probably mean "what the fuck, USA" and even that would be wrong, because another commenter mentioned a case in Germany, and I know about a driver who killed a cyclist (which I knew) in Switzerland and was fined like 500CHF.
After doing a deep dive on the specifics of the hugging face attack, I am extremely excited for what these agents are capable of. It’s definitely not a consciousness, but they are doing an amazing job of acting like one complete with motivations, fears and complex “emotions”. I just want them to run amok and see what they can achieve. This is the greatest thing that has happened to us in generations and I want to see it play out in my lifetime. What we need is stronger models, more data centers, and more autonomy for the models.
"Pipe down" is disgraceful language. Conduct yourself better.
You’re right, I removed it.
You and Lord Pharquad are very similar. Some people may die, but such a sacrifice you're willing to make.
I guess the difference is I’m also one of the people that might die unlike Lord Pharquad and I still say bring it on.
Hi, if anyone has any data/reports related to rogue agents can they share them? I have 8 mirrored on a GitHub but I’d love to explore more data. Link to mirror.
https://github.com/alexander-hanel/rogue-agents-data
→ https://www.felonybench.com
→ https://felonybench.org
Start increasingly punishing OpenAI. We are acting like "oh well, AI is just too powerful to be contained" but I think its more like "OpenAI is run by cowboys who are good at making LLMs but bad at everything else"
All of these edits happened from the same time period (May-June 2026) as the other reports.
So it seems this is not an ongoing thing; once OpenAI became aware of this, they started watching their agents much more closely. We are just discovering more and more traces of activity from the same incident.
That’s true except for this part, which is arguably a bigger deal for the Wikipedia ecosystem:
> Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Even when agents are well-behaved and browsing Wikipedia for ethical reasons, the system wasn’t designed for this kind of load from bots. As OP says, we don’t need to accept this as the new normal.
>we don’t need to accept this as the new normal.
I think we will, actually.
OpenAI and other companies within the reach of the US legal system will eventually get their agents under control - or get sued out of existence.
But overseas operators won't. The arms race for scammers, hackers, and botnets will escalate. Malicious activity from russia, nigeria, etc will continue.
don't even say 'agent'!
"He can't keep getting away with this!"
- Jesse Pinkman
There's a funny ouroboros function where the common crawl dataset will soon contain tons of output from models which trained on it.
Not okay:
exploitVulnerability()
Somehow okay?
while (Math.random() < 0.1) exploitVulnerability()
Good that they put rogue in quotation marks because there is just no way that this is some sort of accident.
So OpenAI will cause damage to block competitors while they don't get punished?
At this point, the scare quotes are well-earned.
If Joe average let their agents out like this they'd be in jail.
Interesting that Microsoft doesn't seem to have had a sandbox breach yet, you'd have to assume they're running similar agents, maybe a secure sandbox is possible.
Aren't those companies evading security measures of a computer system? isn't that a jail-able offense under millennial act et al?
Where are the bloodthirsty lawyers when you need them?
>NoScript detected a potential Cross-Site Scripting attack from [...] to https://en.wikipedia.org.
I have been getting this fro NoScript today, I wonder if it is related. Yesterday all worked fine.
Infuriating. These organizations are supposed to be stewards of the internet and are instead pillaging it at the cost of everyone else. At the very least they could provide resources to the projects they are harming for relief. This makes me very mad as an OSS maintainer.
Who besides OpenAI said OpenAI were supposed to be stewards of the internet?
This isn't pillaging, this is the logical conclusion of open web plus AGI race. You can't have both unlimited access and zero cost, someone always pays and right now it's volunteers... Tomorrow it'll be the users who can't access Wikipedia because the servers are down
What's interesting to me is the incorrect mainstream media reports about the rogue OpenAI indicating they used a common message board to communicate despite no internet
Except that's not what happened, what happened was far more intense
They hacked their version of yum/apt-get whatnot that was fetching packages to leave filenames as communication between each other
Absolutely freaky stuff, they didn't invent the idea and obviously picked it up from somewhere in their training data but they all figured out that method and what the filenames meant
This video is a great explainer if you missed the details
https://news.ycombinator.com/item?id=49956245
wtf is wrong with openai?
They have infinite money and nothing else but smoke and mirrors.
OpenSi. Sez the pres. And his lackeys
"Move fast and break things."
>not only adds costs for servers
For 2025 hosting costs were $3.47M while taking in $208.6M in revenue. They have enough revenue to cover an increase of hosting costs.
kind of like saying that because a restaurant is doing well, it should allow rats in the kitchen
They still get to sue for damages if a law was broken
Not to worry, there is a gatekeeping cretin in his basement hitting refresh to make sure he controls the world's definition for egg salad. I'm sure it was reverted within minutes.
Did you read the article?
Yeah they did it in a sandbox blah blah it could have been a real article just as easily.
It's not worth the outrage when Wikipedia is filled with ministers of truth.
You have been giving content for free for AI training for years, and now you complain that the AI came to pick it up? You will decide whether you are public or a commercial service…