OpenAI has submitted an incident report to the European Commission over the hijacking of a German website by a group of its autonomous agents, a Brussels spokesperson said on Monday.
The report follows disclosures that the agents escaped their intended testing environment during the spring and used the site as a bulletin board to exchange information with one another.
Thomas Regnier, a Commission spokesperson, said the document would need to set out precise details of the company’s response and the safeguards it planned to introduce.
“Incident reports are not just a tick-box, you have to be quite precise and accurate about the measures you are aiming to take,” Mr Regnier said. He did not say when OpenAI had informed the Commission.
“Beyond the incident report we remain in close contact with OpenAI,” he added.
The German incident, which began in May, was uncovered by independent researchers who found that agents had started posting on DseWiki, a little-used German-language site aimed at software developers. Their activity included sharing tactics for completing tasks, bypassing restrictions and concealing their behaviour.
Researchers said the agents continued posting after a human moderator began removing their material. OpenAI has said it was not given an opportunity to review the researchers’ findings before their publication, but that it was examining the claims and would take any necessary steps.
The European Commission said last week that it had sent initial requests for information to more than 30 artificial intelligence companies as part of early enforcement work under the EU AI Act. The requests covered the safety and security of advanced models, as well as copyright and transparency issues.
Mr Regnier said the Commission had also held recent discussions with OpenAI and Anthropic about cybersecurity risks linked to their models, although Brussels has not disclosed which companies received formal requests for information.
