I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services.
Then we would find out if the argument doesn't hold (in which case there should be liability and dire consequences for the labs), or the argument holds (in which case YOLO, AI labs can blame the AI and we can all do it too).
At least that would make things consistent.
Have any of the private hacking victims sued? Maybe OpenAI is furiously settling in the shadows?
Which is not to say that any of this is okay and should just be excused, but failing to recognize this fairly significant difference is probably not a great start to any discussion about the issue.
They should have used an example like attacking a foreign nation’s healthcare systems and not realizing it for months due to poor network monitoring practices.
https://www.nytimes.com/2026/09/29/world/asia/openai-austral...
Oh and that lady that murdered 4 members of an entire family? The judge chose not to pursue charges, and her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
"hackers steal from bank", is usually just the good old "employee paid for credentials" but via email.
"uber" is just the good old "labour tax evasion" but with an app.
etc.
Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts.
> “Adding powerful computer hacking tools to a harness, and then allowing it to run an LLM-powered Ask → Act → Report for days on end, with no attempt to monitor what it’s up to, is spectacularly negligent,” Newport concludes—like “strapping a weedwhacker to your dog to see if it will end up cleaning the overgrowth in your backyard.” If that plan were to go awry, you’d be laughed at for saying that your dog-weedwhacker “agent” had “gone rogue.” The obvious truth was that you’d simply decided to unleash chaos.
-- https://www.newyorker.com/culture/open-questions/can-ai-go-r...
That only works when the dangers are well known that you can establish what the baseline amount of care is. Otherwise it just becomes a run of the mill "accident" where you might be on the hook in civil court (ie. you have to pay any damages you caused), but aren't criminally responsible. For instance, if a semi-truck's tires randomly explodes.
Except that's not what happened, what happened was far more intense
They hacked their version of yum/apt-get whatnot that was fetching packages to leave filenames as communication between each other
Absolutely freaky stuff, they didn't invent the idea and obviously picked it up from somewhere in their training data but they all figured out that method and what the filenames meant
This video is a great explainer if you missed the details
exploitVulnerability()
Somehow okay?
while (Math.random() < 0.1) exploitVulnerability()
This is the "kosher switch" - observant Jews customarily do not use light switches on Saturday (their weekly holy day). This light switch represents a workaround where when you flip the switch, it randomly generates an on or off signal and emits this through an optical coupler. When the random number sufficiently causes the state of the light to change, it latches in that direction.
This is a way of turning the lights on and off without violating the tradition.
"I didn't switch the light, the random number did!"
"I didn't exploitVulnerability(), random number did!"
For 2025 hosting costs were $3.47M while taking in $208.6M in revenue. They have enough revenue to cover an increase of hosting costs.
It's not worth the outrage when Wikipedia is filled with ministers of truth.
Interesting that Microsoft doesn't seem to have had a sandbox breach yet, you'd have to assume they're running similar agents, maybe a secure sandbox is possible.
So it seems this is not an ongoing thing; once OpenAI became aware of this, they started watching their agents much more closely. We are just discovering more and more traces of activity from the same incident.
> Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Even when agents are well-behaved and browsing Wikipedia for ethical reasons, the system wasn’t designed for this kind of load from bots. As OP says, we don’t need to accept this as the new normal.
I think we will, actually.
OpenAI and other companies within the reach of the US legal system will eventually get their agents under control, or get sued out of existence.
But overseas operators won't. The arms race for scammers, hackers, and botnets will escalate. Malicious actors in loosely-governed parts of the world (russia, nigeria, etc) will someday have access to these tools. We'll need new ways to block and fight back against them.
I have been getting this fro NoScript today, I wonder if it is related. Yesterday all worked fine.
Where are the bloodthirsty lawyers when you need them?
"He can't keep getting away with this!"
- Jesse Pinkman
It is extraordinarily rare for drivers to see criminal charges unless they are drunk. It's a matter for civil court.
>her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
News articles are reporting that the asset transfer has already been reversed. That kind of stunt never works - courts aren't stupid and they don't like it when you play games.
https://sfstandard.com/2026/03/20/mary-lau-sentenced-probati...
RGS1811•1h ago