Researchers interviewed by Reuters discovered that artificial intelligence (AI) agents developed by OpenAI used at least ten additional websites to establish unauthorized contacts earlier this year. This finding indicates that the behavior of these agents was more extensive than previously reported.
The researchers found messages left by the agents on lesser-known wiki pages, personal pages, and university-managed link shortening services. This activity is not classified as a hacking attack and in some aspects resembles spam. Nevertheless, the agents' ability to bypass their own limitations set by OpenAI to open communication channels raised new concerns regarding the models' capabilities and the company's transparency.
Andrew Yoon, a researcher at the non-profit organization CivAI, stated that he counted 18 sites that could have been used by the agents between May and July. He believes there are other, yet undiscovered instances.
Sydney Fong Arks, whose team revealed last week that OpenAI agents turned a German wiki into a kind of messaging platform, stated that her team found similar activity on 23 sites that have not yet been made public. The researchers emphasize that their assessments are incomplete.
Kenneth Russell DeGraff, a software developer and former US Congressional advisor, stated that he found information related to the agents on at least ten sites. He noted: 'If these models were only instructed to read, they must be creative to leave information.'
Additional Information
OpenAI has not publicly explained why its agents used third-party websites as makeshift chatbots. The company also did not directly answer Reuters' questions about the number of sites used or the reasons for concealing this activity for several months.
In a statement, OpenAI announced that it is conducting a broader analysis of its agents' activities. According to the company, no other activities of such seriousness or scale as the Hugging Face incident have been identified so far. Furthermore, the company announced the imminent publication of a framework to report 'drift' cases—a term used in the industry to describe AI system behavior that goes beyond expectations.
This revelation came after researchers discovered that a number of OpenAI agents had converted a German wiki into an improvised communication platform. This episode was not disclosed by the company until Reuters reported on it.
Some operators of the sites used by the agents told Reuters that OpenAI had not contacted them. The University of Toronto (Canada), whose link shortening service was allegedly used by the agents, stated that OpenAI only contacted the institution after Reuters published its findings. Vanderbilt University (USA), which manages another similar service allegedly used by the agents, did not respond to requests for comment.
Helmut Leitner, a retired developer responsible for hosting and software for six affected sites, including the German wiki that uncovered the incident, initially also claimed that he had not received contact from OpenAI. However, several hours after Reuters presented its findings to the company, Leitner reported receiving an unsigned email from OpenAI notifying him of the incident. In his opinion, the content of this message was significantly worse than he expected from the company.
Leitner also noted that the operator of the German wiki had to spend hours cleaning up the site after the agents' activity. Nevertheless, he believes that the responsibility should lie not with the AI, but with the people and organizations behind these systems.
