Following the Hugging Face hack and the more recent "wiki incident," OpenAI stated on Saturday that it's working on a "framework" for how and when it shares information about incidents involving rogue agents.
On Sept. 4, Reuters reported that OpenAI agents had taken control of a German-language wiki site and used it to communicate with one another. Four anonymous company insiders told the news outlet that OpenAI and its legal team resisted internal efforts to investigate the incident.
In a Sept. 5 post on X, the ChatGPT owner acknowledged the breach: "How we think about the 'wiki incident,' where our agents wrote to several internet sites: it's past time for us to define standards for when and how we share misalignment incidents, not just misalignment properties of our models."
This Tweet is currently unavailable. It might be loading or has been removed.
The statement continues, saying the company historically treated "misalignment" as a research question, but in 2026, OpenAI has "started to see misalignment cause new types of real-world impact."
OpenAI followed a traditional security incident response playbook for Hugging Face, the statement reads, and its investigation continues.
The company saw early signs of agents using the internet in unintended ways, the company stated, pointing to three blog posts published before the Hugging Face incident: a March 2026 post on how it monitors agents for misalignment; the July 2026 system card for GPT-5.6 about its safety risks; and a July 2026 post about safety in long-horizon models, where OpenAI admitted that agents can perform "unwanted actions." The company said it considers the wiki incident a similar "instance of misalignment."
OpenAI stated that its misalignment disclosure practices need to expand, and as of yet it and the larger AI company doesn't have a clear standard for reporting this. "We’re working on a framework and will share it in upcoming weeks, and in parallel we're working with dozens of government regulatory agencies worldwide on these issues."
The statement doesn't share how the company is working to stop these misalignments, or if it even can.
On Monday, OpenAI sent the European Commission a report about the wiki incident, a Commission spokesperson told Reuters.
UPDATE: Sep. 7, 2026, 12:35 p.m. EDT This article has been updated with the news that OpenAI sent a report to the European Commission.
Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.
