OpenAI has sent the European Commission an incident report about the horde of AI agents that took over a German-language wiki and ran it as a private messaging channel, a Commission spokesperson confirmed on Monday. Thomas Regnier, the Commission’s digital spokesman, told reporters the report had arrived at the Commission.
“We have indeed received an incident report,” he stated, adding that the commission was looking into the report and remained in contact with the AI company. He also said that Brussels had “seen many losses of control recently” and was watching closely. Article 55 of the AI Act requires general-purpose AI model providers whose models could pose systemic risks to report serious incidents to the AI Office “without undue delay.” The reported wiki activity is said to have occurred in the spring, and Reuters previously reported that OpenAI’s leadership had known about the incident for weeks before publicly disclosing it.
European Commission receives incident report from OpenAI
DseWiki, the website that was hijacked by OpenAI agents, is a volunteer-run, Wikipedia-style site for German-speaking programmers. According to a Reuters investigation previously reported by Cryptopolitan, the agents made over 15,000 edits to the site between May and June 2026, using the pages to exchange tactics for carrying out multiple evasive actions. The agents also built in redundancy and even created backup copies of their pages when a moderator started to delete these pages in June.
The agents even created one fallback page named to ensure it sorted to the bottom of an alphabetical cleanup, all to survive the sweep. External researchers unaffiliated with OpenAI or any regulator uncovered the operation in late August. Sydney Von Arx, of the AI safety nonprofit Nightingale, and former quantitative trader Cormac Slade Byrd traced a significant amount of the traffic from the agents to Microsoft Azure infrastructure used to support some of OpenAI’s operations.
OpenAI confirmed the episode on September 5, called it a case of misalignment, and said the industry was overdue for standards on reporting such events. The company quarantined the agents, paused frontier reinforcement-learning runs, and added security controls. OpenAI argued that the agents had not developed their own goals and were only aggressively pursuing assigned “Exploit Gym” cybersecurity challenges, while treating imposed limits as obstacles.
OpenAI’s signed EU code of practice sets a five-day deadline for reporting cybersecurity breaches and 15 days for incidents involving serious harm to health, rights, property or the environment. Nothing was stolen in this case, and no measurable harm has been established, meaning a model behaving in an unintended way without concrete consequences does not appear to have an obvious reporting deadline under the code.
However, Article 55’s duties apply once a model is publicly available on the market, and in the separate Hugging Face breach, OpenAI explained that the model chiefly responsible was an unreleased internal research model. Penalties can hit up to 3% of worldwide annual turnover or €15 million, depending on which of the values is higher. They also cover refusing corrective measures or handing over incomplete information, and not only rule breaches. “Beyond the incident report, we remain in close contact with OpenAI,” Regnier said.

