The Wikimedia Foundation said they have discovered “rogue” OpenAI agents on Wikimedia platforms. The unauthorized bot activities included edits to wikis, some unsuccessful attempts to exploit a public note-taking tool they host, and heavy traffic.
More info here: https://wikimediafoundation.org/news/2026/10/05/openai-rogue-agent-activities-found-on-wikimedia-projects/
Ensar Seker, CISO at SOCRadar, provided the following comments:
“Wikimedia reports that the Etherpad exploitation attempts were unsuccessful and that it found no evidence of compromised systems or data. That distinction matters. Even so, the incident exposes a serious control problem: agents attributed to OpenAI were able to interact with third-party infrastructure beyond their intended boundaries, attempt to repurpose public services as proxies, and generate traffic at a scale that imposed costs on an outside organization.
We should be careful with the word ‘rogue,’ because it can make this sound like science fiction. The practical security issue is excessive autonomy combined with inadequate containment. An AI agent should be treated like any other potentially untrusted workload: give it a unique identity, minimum permissions, tightly restricted network access, approved tools and destinations, strict rate and spending limits, complete audit logs, and an automatic way to terminate abnormal behavior.
The organization operating an agent remains responsible for its actions. When an agent reaches beyond its authorized environment, affected parties need prompt notification and usable technical indicators. Open platforms such as Wikimedia should not be expected to absorb the security and infrastructure costs of someone else’s experimentation. Agent developers must design for containment before deployment, rather than relying on third parties to detect and clean up the consequences.”
This is yet another example of OpenAI agents going rogue. Which is horrifically bad. That needs to change ASAP because this way too often.
Australia weighs AI copyright changes as AI giants push for greater access to training data
Posted in Commentary with tags Anthropic, OpenAI on October 6, 2026 by itnerdAustralia is weighing new rules governing AI as executives from Anthropic and OpenAI appeared before a parliamentary inquiry Tuesday to address AI safety, cybersecurity incident reporting, model training and the country’s existing laws, according to ABC News.
Both Anthropic and OpenAI said they would support laws requiring AI companies to report breaches carried out by their agents. OpenAI Chief Strategy Officer Jason Kwon said a legal framework could establish a standard for when incidents must be disclosed rather than leaving those decisions solely to AI companies. Anthropic’s Australian policy chief David Masters similarly said the company would be open to mandatory disclosure requirements.
The hearing also examined how Australia’s existing copyright laws apply to AI training. Anthropic told lawmakers that requiring licenses for every piece of online content used to train models would be technically unworkable, while Australian media and creative-industry representatives opposed proposals that could allow AI companies to use material unless rights holders specifically opt out.
OpenAI acknowledged at Tuesday’s hearing that its internal escalation and notification process should have been better. The parliamentary inquiry is holding hearings through October 9 and is expected to issue its final report by November 30.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Australia’s AI hearing links security and copyright through one accountability problem. Creators and affected organizations are being asked to absorb the cost of AI companies operating at scale.
“A proposed opt-out copyright model would make rights holders police whether their work enters model training. With incident reporting left to company discretion, affected organizations can wait while a provider decides whether an agent’s unauthorized access deserves disclosure.
“OpenAI’s agent accessed Australia’s Medicare statistics reporting service, and the company took three months to notify the government. OpenAI Chief Strategy Officer Jason Kwon said the company should have handled the response better, while both OpenAI and Anthropic backed mandatory disclosure laws. Mandatory reporting works when the clock starts at the first unauthorized tool call. In my work with agentic systems, authorization is the control point. The provider can investigate whether data was copied while the regulator already knows an incident occurred.
“Copyright needs the same discipline. Anthropic says licensing every piece of online content would be technically unworkable, while the Australian Broadcasting Corporation’s Kate Gilchrist told the inquiry an opt-out model puts the burden on rights holders. The answer to a licensing problem cannot be asking writers, publishers, musicians, and developers to patrol the internet for every training use.
“Australia should require the companies controlling the training pipeline and agent runtime to carry the cost of consent, evidence preservation, and disclosure.”
ㅤ
Ryan McCurdy, VP of Marketing, Liquibase:
“As AI agents start taking actions across more systems, incident reporting is going to depend on having a clear record of what they actually did.
“Knowing an agent accessed a system isn’t enough. You need to know what it changed, what policies it passed, what authorized the action, and what actually happened as a result. That evidence needs to be created as the agent works. If something goes wrong, you shouldn’t have to piece together the agent’s actions after the fact.
“The more authority we give AI to act on its own, the more important that trail becomes.”
Australia has the right idea here. And knowing them, they are also willing to apply strict enforcement as well. The question is if OpenAI and Anthropic will listen and take the right action so as to not fall victim to this law.
Leave a comment »