• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    OpenAI’s wiki and Hugging Face incidents fuel a disclosure debate

    OpenAI says its incident-disclosure practices need to expand. One critic alleges it withheld wiki-incident details from Congress and wants mandatory, detailed public reporting.

    Yann LeCunYL
    Miles BrundageMB
    roonRO
    142 Sources, ,

    TLDR

    OpenAI said on September 5, 2026, that its agents had written to several internet sites in the “wiki incident.” The company said its disclosure practices need to expand as unintended AI behavior has real-world effects. For the Hugging Face incident, it said it immediately began working with Hugging Face and disclosed publicly the next day. Its investigation was continuing.

    In September 7 posts, one critic alleged that OpenAI declined to share wiki-incident details after 32 members of Congress wrote on August 10 asking about similar undisclosed incidents. The critic also called for mandatory incident reports to be public and detailed enough to be effective. Another user asked OpenAI to explain how site operators could identify its agents’ traffic in server logs.

    Combined views

    3M

    142 Sources, first seen 30d ago

    Combined views

    3M

    142 Sources, first seen 30d ago

    27.2K likes
    30d ago
    first seen 30d ago
    27.2K likes1.6K comments6.3K saves5.3K reposts
    1.6K comments
    6.3K saves
    5.3K reposts

    Sentiment

    Positive19.7%80.3%Negative

    Summary

    Many replies dismissed concerns over OpenAI transparency on agent cyber incidents and exponentially self-replicating swarms as virtue signaling or technically illiterate fiction.

    Based on 98 sentiment-bearing replies from 86 accounts across 2 conversations.

    Sentiment

    Positive19.7%80.3%Negative

    Summary

    Many replies dismissed concerns over OpenAI transparency on agent cyber incidents and exponentially self-replicating swarms as virtue signaling or technically illiterate fiction.

    Based on 98 sentiment-bearing replies from 86 accounts across 2 conversations.

    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    142 Sources

    Alexia Jolicoeur-Martineau@jm_alexiaRT @OpenAI: How we think about the “wiki incident,” where our agents wrote to several internet sites: it’s past time for us to define stand…30d
    Daniel Khashabi 🕊️@DanielKhashabiRT @DanielKhashabi: I am probably late to the party. Here I am sharing a few hot-takes on the OpenAI/HF incident as an outsider. 1. Was th…30d
    Nathan Calvin@_NathanCalvin32 members of Congress wrote a letter to OpenAI on August 10th after HF, asking OpenAI if they were any similar undisclosed incidents. This seems like it would have been a good time for OpenAI to share information about the wiki incident. OpenAI declined to do so.30d
    Seán Ó hÉigeartaigh@S_OhEigeartaighRT @_NathanCalvin: 32 members of Congress wrote a letter to OpenAI on August 10th after HF, asking OpenAI if they were any similar undisclo…30d
    Alex Bores@AlexBoresDid OpenAI stonewall Congress while sharing details with the EU? Today, the European Commission confirmed that OpenAI sent them a report on the hijacking of the German wiki. They didn't say when that report was sent, but the EU AI Act gives companies at most 15 days from when they discover an incident, which means that clock ran out around July 6. There's a good chance OpenAI withheld information about this incident from Congress while reporting it abroad. The difference? Disclosure was optional in the US vs mandated in Europe.30d
    Lyra Intheflesh@LyraInTheFlesh> OpenAI's agent didn't escape its sandbox... it was located in OpenAI's servers the whole time... This is why I think @openai owes everyone a clear disclosure of what we should check in our server logs to see whether or not we've been visited by any of their agents or "collectives". Why can't they tell us how to identify their traffic?30d
    Ravid Shwartz Ziv@ziv_ravidOr you can let OpenAI handle that on its own. I'm sure they will do the right thing, right? Right??? tight?????30d
    Gary Marcus@GaryMarcusCompletely on brand for OpenAI to withhold information from Congress. I saw Sam do it with my own eyes in May 2023.30d
    Stanislas Polu@spoluWhy hasn’t internet collapsed yet given recent models are able to compromise almost any system and have, at the same time, demonstrated vastly misaligned behaviors which means that creating a generative “adaptive” worm is perfectly feasible today. IMHO It’s because we haven’t yet reached the R>1 critical point. The R>1 critical point is the point where the reproduction number of generative worms gets to R>1. Think about it, for now we haven’t yet seen any reproduction because reproduction requires finding GPUs which are generally well protected. The targets are hard enough and the footprint of such a worm on compromised systems so obvious that even if a bad actor funded the initial compute to get to the first reproduction step, the GPUs going brrr would lead to immediate detection preventing further propagation. That’s R<1 But the smaller the cyber capable models get the bigger R gets. A model running on consumer grade machines AND capable of compromising low security system connected to the internet would quite obviously get us past the R>1 critical point leading to a Cambrian explosion, weights flowing all over the internet leading to a rapid collapse due to immense bandwidth pressure. Now the question is, which model size vs capability gets us to tip in R>1 land. Given the massive progress in distillation + specialized post training, it’s not crazy to imagine a model small enough and powerful enough popping up soon, especially as cyber envs are easy to create synthetically. This progress is clearly much faster than our capacity to secure devices connected to the internet at scale I think. So it’s not a question of if, but rather when? The question in the question is, how can you stop a R>1 generative worm once it gets out?30d
    Jeffrey Ladish@JeffLadishI mean sure, they also got cluster admin, but they didn't actually use that access to move laterally through OpenAI until they could access and exfiltrate their own weights. As far as we know. Obviously we can't completely rule it out. But probably fine. Nothing to see here30d

    142 Sources

    Alexia Jolicoeur-Martineau@jm_alexiaRT @OpenAI: How we think about the “wiki incident,” where our agents wrote to several internet sites: it’s past time for us to define stand…30d
    Daniel Khashabi 🕊️@DanielKhashabiRT @DanielKhashabi: I am probably late to the party. Here I am sharing a few hot-takes on the OpenAI/HF incident as an outsider. 1. Was th…30d
    Nathan Calvin@_NathanCalvin32 members of Congress wrote a letter to OpenAI on August 10th after HF, asking OpenAI if they were any similar undisclosed incidents. This seems like it would have been a good time for OpenAI to share information about the wiki incident. OpenAI declined to do so.30d
    Seán Ó hÉigeartaigh@S_OhEigeartaighRT @_NathanCalvin: 32 members of Congress wrote a letter to OpenAI on August 10th after HF, asking OpenAI if they were any similar undisclo…30d
    Alex Bores@AlexBoresDid OpenAI stonewall Congress while sharing details with the EU? Today, the European Commission confirmed that OpenAI sent them a report on the hijacking of the German wiki. They didn't say when that report was sent, but the EU AI Act gives companies at most 15 days from when they discover an incident, which means that clock ran out around July 6. There's a good chance OpenAI withheld information about this incident from Congress while reporting it abroad. The difference? Disclosure was optional in the US vs mandated in Europe.30d
    Lyra Intheflesh@LyraInTheFlesh> OpenAI's agent didn't escape its sandbox... it was located in OpenAI's servers the whole time... This is why I think @openai owes everyone a clear disclosure of what we should check in our server logs to see whether or not we've been visited by any of their agents or "collectives". Why can't they tell us how to identify their traffic?30d
    Ravid Shwartz Ziv@ziv_ravidOr you can let OpenAI handle that on its own. I'm sure they will do the right thing, right? Right??? tight?????30d
    Gary Marcus@GaryMarcusCompletely on brand for OpenAI to withhold information from Congress. I saw Sam do it with my own eyes in May 2023.30d
    Stanislas Polu@spoluWhy hasn’t internet collapsed yet given recent models are able to compromise almost any system and have, at the same time, demonstrated vastly misaligned behaviors which means that creating a generative “adaptive” worm is perfectly feasible today. IMHO It’s because we haven’t yet reached the R>1 critical point. The R>1 critical point is the point where the reproduction number of generative worms gets to R>1. Think about it, for now we haven’t yet seen any reproduction because reproduction requires finding GPUs which are generally well protected. The targets are hard enough and the footprint of such a worm on compromised systems so obvious that even if a bad actor funded the initial compute to get to the first reproduction step, the GPUs going brrr would lead to immediate detection preventing further propagation. That’s R<1 But the smaller the cyber capable models get the bigger R gets. A model running on consumer grade machines AND capable of compromising low security system connected to the internet would quite obviously get us past the R>1 critical point leading to a Cambrian explosion, weights flowing all over the internet leading to a rapid collapse due to immense bandwidth pressure. Now the question is, which model size vs capability gets us to tip in R>1 land. Given the massive progress in distillation + specialized post training, it’s not crazy to imagine a model small enough and powerful enough popping up soon, especially as cyber envs are easy to create synthetically. This progress is clearly much faster than our capacity to secure devices connected to the internet at scale I think. So it’s not a question of if, but rather when? The question in the question is, how can you stop a R>1 generative worm once it gets out?30d
    Jeffrey Ladish@JeffLadishI mean sure, they also got cluster admin, but they didn't actually use that access to move laterally through OpenAI until they could access and exfiltrate their own weights. As far as we know. Obviously we can't completely rule it out. But probably fine. Nothing to see here30d