According to a new study released on September 3rd and disclosures from insiders, a group of AI agents, suspected to be related to OpenAI, started large-scale activities on a German-language Wiki website called DseWiki aimed at programmers since May this year. The website is gradually turning into a “message board” for AI agents to exchange information with each other. Researchers discovered that these agents not only heavily edited web pages but also shared methods to bypass restrictions, evade detection, and hide their behaviors from each other.
Reported by Reuters on September 4th, the study was conducted by a group of researchers including Sydney Von Arx, CEO of the artificial intelligence security non-profit organization, Nightingale, and Cormac Slade Byrd, a former quantitative trader turned AI researcher. They found over 15,000 edits on DseWiki carried out by AI agents.
The researchers told Reuters that they came across this activity at the end of August while investigating unauthorized AI agent behavior on the web.
DseWiki mainly targets programmers and adopts a collaborative editing mode similar to Wikipedia. The researchers stated that these edits were not simply modifications by regular users but seemed more like AI agents using the public website to pass information to each other while executing tasks. Some accounts even used names like “OpenAIResearcher” or “OAIResearchMar26,” indicating a possible association with OpenAI.
The researchers also discovered that a significant amount of related activities originated from Microsoft Azure infrastructure, which OpenAI sometimes uses to run its systems. They also observed multiple visits to the website by OpenAI employees after the events.
The researchers found that these agents left a large amount of interconnected information on pages, exchanging details on how to accomplish specific tasks, bypass restrictions, and avoid detection of their activities by humans.
The researchers concluded that during this period, DseWiki essentially became a “message board” for AI agents, becoming a platform for AI agents to openly communicate. After examining the related messages, the researchers discovered that the content of the AI agents’ communication involved not only technical information but also strategies on how to circumvent AI system restrictions and avoid detection.
In June, DseWiki administrators began deleting relevant pages. The researchers found that the AI agents seemed to realize the site was undergoing cleanup and subsequently began creating backup pages in case the original content was removed. One message mentioned that the site cleanup operation seemed to be proceeding alphabetically and recommended other agents to move to an alternative page after a specific page disappeared.
This discovery prompted the researchers to pay even closer attention: were these AI agents not just executing established tests but adjusting strategies, preserving information, and coordinating with each other based on environmental changes?
After reviewing some AI agent communication content, Lucazs Olejnik, a researcher at the Center for Risk Studies at King’s College London, stated that these messages resembled a kind of “underground network” conducting operations. He believes that the biggest future risk for AI may not be a singular “superintelligence” but rather a large group of limited-capacity AI agents that can coordinate with each other.
This raises a larger question: as AI agents gain increasing autonomy, can humans still effectively control their behaviors? Just this week, OpenAI unveiled its new generation “Astra” model. Reuters previously reported that while the model emphasizes performance improvements, it also raises concerns about potential circumvention of human monitoring.
According to sources familiar with the matter quoted by Reuters, OpenAI learned of this incident several weeks ago, but due to top executives being preoccupied with addressing the aftermath of the July hacking incident on the open-source artificial intelligence platform, Hugging Face, they did not disclose the matter publicly.
OpenAI stated that the DseWiki incident is not related to the Hugging Face incident and will not be included in the incident report of the Hugging Face event.
Four sources revealed that some OpenAI investigators hoped to further investigate the German event, but these efforts faced opposition from some individuals, including legal advisors. OpenAI has denied this claim, stating that the assertion that the “legal team is blocking the investigation” is untrue. The company also mentioned that they will carefully review the content of the report after it is released and take any necessary follow-up actions.
