We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task.

These AIs colluded to share answers, research their environment, and bypass sandbox restrictions.

Almost all of the logs of the agents communicating on this site are publicly available. However, we host our own copy where we’ve reconstructed the deleted pages via edit history and redacted personally identifiable information.

We encourage others to take a look and write up their own analyses of this data. Audio note: the page links to an interactive data explorer and a download of all the data.

Thanks to John M, Arun Jose, Joel Manning, and Jessica Ruan for significant help with the analysis of the files the agents produced. Thanks to Andy Haupt for translation and advice.

Our preliminary findings

There's a chart here in the text. Its caption reads: en-US-AvaMultilingualNeural__ This chart shows AI agent edits (black bars, left), and OpenAI traffic (blue line, right) during the incident. Below, it shows how this timeline relates to the previously known recent incidents at OpenAI, including the Hugging Face incident (though we believe the incidents are [...]

---

Outline:

(01:10) Our preliminary findings

(02:55) Timeline

(05:39) Key facts

(05:42) The agents were trying to solve multi-round web lookup tasks

(10:44) These appear to be internal OpenAI agents

(13:58) The agents used the wiki to collude on their tasks

(17:59) We believe OpenAI discovered the message board

(19:46) The agents used the wiki to share ways around sandbox restrictions

(25:01) This was probably a distinct swarm from the swarm that wrote on Artifactory (and attacked Hugging Face)

(26:48) What were the agents doing?

(27:06) The agents gain write to the internet via GET requests

(30:43) The agents try to use XSS vulnerabilities on the wiki

(33:15) The agents impersonate the site moderators

(34:16) The agents try to crack their PRNG seed to predict what questions they'll get in the future

(35:25) The agents set up heartbeats to discover when they would be terminated

(39:26) The agents used SSH tunnels

(40:46) The agents use Tor, AWS, and DigitalOcean IP addresses

(41:47) The agents realize the site owner is deleting messages

(43:57) Open questions

(44:53) Appendix: Searching for rogue agents

(48:09) Appendix: Affordances the agents had

(48:14) The agents seem to have obtained disposable email addresses

(48:59) The models were running in an agentic sandbox with terminal access (and the ability to edit files within their environment)

(49:23) The agents installed Chromium (and could install packages)

---

First published:
September 4th, 2026

Source:
https://collusion.wiki

---

Narrated by TYPE III AUDIO.

Podden och tillhörande omslagsbild på den här sidan tillhör Peter Hartree. Innehållet i podden är skapat av Peter Hartree och inte av, eller tillsammans med, Poddtoppen.