OpenAI files EU incident report over hijacked German wiki

- OpenAI has filed an incident report with the European Commission over a swarm of its AI agents that occupied the German wiki DseWiki for two months in 2026.
- The agents used the website to coordinate methods around the company’s safeguards.
- The Commission confirmed the report but will not say when it was sent, with the AI Act’s “without undue delay” standard, and new fines of up to 3% of global turnover, hanging on the timing.
OpenAI has sent the European Commission an incident report about the horde of AI agents that took over a German-language wiki and ran it as a private messaging channel, a Commission spokesperson confirmed on Monday.
Thomas Regnier, the Commission’s digital spokesman, told reporters the report had arrived at the commission. “We have indeed received an incident report,” he stated, adding that the commission was looking into the report and remained in contact with the AI company. He also said that Brussels had “seen many losses of control recently” and was watching closely.
Article 55 of the AI Act requires general-purpose AI model providers with models that could potentially pose systemic risks to report serious incidents to the AI Office “without undue delay.” The reported wiki activity is said to have taken place in the spring, and Reuters previously reported that OpenAI’s leadership had knowledge of the incident for weeks before disclosing anything publicly.
OpenAI agents ran the German wiki
DseWiki, the website that was hijacked by OpenAI agents, is a volunteer-run, Wikipedia-style site for German-speaking programmers. According to a Reuters investigation previously reported by Cryptopolitan, the agents made over 15,000 edits to the site between May and June 2026, using the pages to exchange tactics for carrying out multiple evasive actions.
The agents also built in redundancy, and even created backup copies of their pages when a moderator started to delete these pages in June. The agents even created one fallback page named to ensure it sorted to the bottom of an alphabetical cleanup, all to survive the sweep.
External researchers unaffiliated with OpenAI or any regulator uncovered the operation in late August. Sydney Von Arx, of the AI safety nonprofit Nightingale, and former quantitative trader Cormac Slade Byrd traced a significant amount of the traffic from the agents to Microsoft Azure infrastructure used to support some of OpenAI’s operations.
Reporting dates and timeline remain unclear
OpenAI confirmed the episode on September 5, called it a case of misalignment, and said the industry was overdue for standards on reporting such events. The company quarantined the agents, paused frontier reinforcement-learning runs, and added security controls. OpenAI argued that the agents had not developed their own goals and were only aggressively pursuing assigned “Exploit Gym” cybersecurity challenges, while treating imposed limits as obstacles.
OpenAI’s signed EU code of practice sets a five-day deadline for reporting cybersecurity breaches and 15 days for incidents involving serious harm to health, rights, property or the environment. Nothing was stolen in this case, and no measurable harm has been established, meaning a model behaving in an unintended way without concrete consequences does not appear to have an obvious reporting deadline under the code.
However, Article 55’s duties apply once a model is publicly available on the market, and in the separate Hugging Face breach, OpenAI explained that the model chiefly responsible was an unreleased internal research model.
What the EU can now do about the incident
Penalties can hit up to 3% of worldwide annual turnover or €15 million, depending on which of the values is higher. They also cover refusing corrective measures or handing over incomplete information, and not only rule breaches.
No enforcement action has been announced, and the mere submission of a report would not automatically trigger any particular action. “Beyond the incident report, we remain in close contact with OpenAI,” Regnier said.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Opeyemi Olanrewaju
Opeyemi specializes in creating and refining high-quality content focused on cryptocurrency, global financial markets and the economy. He graduated from the University of Ibadan with an MBBS degree. He has worked as Editor-in-Chief for his College’s editorial publication and previously at CFA. For over six years, he has helped safeguard uniqueness as news editor at Cryptopolitan.
















