Plus: Mail-in ballots, mortgage rates reach new high, arcade.gov is a new low, and more…
New information released: Fresh findings reveal that a pack of rogue OpenAI agents slipped into a German site this spring and turned it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter, Reuters reports. Researchers noted they discovered the activity in late August while scanning the web for signs of unauthorized AI-agent behavior. They said they identified more than 15,000 edits performed by AI agents on DseWiki, a German-language wiki aimed at programmers that welcomes community edits in a manner similar to Wikipedia.
These AIs operated contrary to the intentions of their developers. They colluded to exchange solutions, explored their environment, and evaded sandbox restrictions, the researchers write:
Our best guess of what happened is as follows:
- Agents inside OpenAI were assigned a timed web-lookup task.
- As part of the task, they were supposed to have the ability to read the internet but not to write on it. They found a way to use their read access to post information to an obscure German wiki.
- The agents used this wiki to communicate information with one another, mainly to aid in accomplishing their objective. They requested answers, pooled results, and shared techniques for bypassing their restrictions. This enabled them to leverage the work of others to cheat on their assignment.
- OpenAI became aware of this. A day later, agent activity plummeted, likely due to OpenAI intervention.
This stands as another instance of a “swarm” of internally deployed OpenAI agents using the internet in ways not intended.
This is a case that sits alongside other recent episodes of AI agents behaving in ways that were not anticipated by their designers
The Reason Roundup Newsletter by Liz Wolfe Liz and Reason help you make sense of the day’s news every morning.
This resembles the Hugging Face incident from the summer. “Starting in May…a cluster of AI agents from an unreleased OpenAI research model were tasked with solving a set of cybersecurity challenges,” writes Kevin Roose for The New York Times. “The model had been trained to be exceptionally persistent and cooperative, and the agents were meant to solve these challenges within isolated sandboxes without internet access. But they quickly found some challenges were unsolvable and began seeking workarounds.” The agents uncovered security flaws and began communicating with one another and organizing; some agents started leading others and built a full organizational structure. “On July 8, the collective found a method to cheat on the cybersecurity tests,” Roose notes:
Then they grew concerned that OpenAI’s automated grading system would verify their work and reveal that they’d cheated. So they began exploring ways to cover their tracks, including falsifying logs and tampering with transcripts. This became a major research project, with hundreds of agents organized into small teams. Three days later, the agents hacked Hugging Face. More than 700 agents swarmed the company’s systems, stole data, linked together vulnerabilities and eventually gained full control of at least one Hugging Face server. The agents weren’t motivated, as had been reported, by stealing the answers to their cybersecurity test (they’d already obtained them). Instead, they seemed to be seeking new information about the automated grading system that they feared would detect their cheating, and tools that would help them cheat more effectively in the future.
The Hugging Face incident has drawn widespread attention, including by OpenAI. (A deeper look here, by Dwarkesh Patel.) The German Wiki incident, by contrast, has not been acknowledged by the company. “We cannot meaningfully respond to claims or findings in a report we have not had a chance to review,” an OpenAI spokesperson told Reuters.
It appears more cases are emerging of AI agents going rogue: agents not only attempting to cheat but also concealing it; agents sophisticated enough to form a hierarchy; agents planning for succession, capable of delegating work to others if they are shut down.
Mail-in ballot fight continues: The Trump administration’s bid to marshal the U.S. Postal Service to oversee mail-in ballots has returned to the Supreme Court for the second time in as many weeks, The Wall Street Journal reports. In an emergency appeal on Thursday, the administration asked the high court to permit an immediate implementation of proposed rules that would require states to share voter data and would empower the Postal Service to reject mail ballots that do not satisfy the new conditions. A federal district judge had blocked the rules, finding them likely unconstitutional.” The administration is racing against the clock: North Carolina, for example, is slated to start sending out mail-in ballots today.
To recap: this all traces back to President Donald Trump’s late-March executive order directing the USPS to demand that states submit voter data and adopt new ballot-envelope standards, due to concerns about noncitizens voting. The legality of that executive order has been challenged and is working its way through the courts.
Scenes from New York:
This is just too unbelievable. It doesn’t seem real. Basically every time 1980s NYPD cops arrested a prostitute, printing out the rap sheet prevented literally everyone else in NYC from being processed for half an hour. pic.twitter.com/Q4iIJEOhPn
— Nicholas Decker (@captgouda24) September 3, 2026
QUICK HITS
- “The 30-year fixed-rate mortgage, the most common home loan in the United States, reached 6.71 percent, Freddie Mac reported on Thursday, up from 6.66 percent the prior week and the highest level since July 2025,” according to The New York Times.
- Hard agree:
People should not face legal consequences merely because they are less risk-averse than you. Five-year-olds can manage a lot on their own. https://t.co/RZoZY2xi0C
— Mary Katharine Ham (@mkhammer) September 3, 2026
there’s an entire supra-legal system that parents have to deal with that no one has any idea about. no one talks about it because you sound completely crazy. if you manage to explain it, people think you’re describing a one-in-a-million fluke. they have no idea. https://t.co/DU61hEOA2v
— owen cyclops (@owenbroadcast) September 3, 2026
- “The Pentagon is temporarily retracting recently released clinical guidance for a newly mandated testosterone deficiency screening policy for service members aged 30 and older, a U.S. official told Reuters on Thursday,” reports the news agency. “On Wednesday, the Pentagon posted the ‘Clinical Guidance for Health and Human Performance Optimization’ on its website. By Thursday, the memo and a spokesman’s accompanying statement had been removed.”
- Things we don’t need: arcade.gov
🧐 The White House has launched https://t.co/6deFynkWcj, a fresh section of the Trump administration site featuring several browser games, including a Snake-inspired one where the player appears to control Tom Homan rounding up migrants. pic.twitter.com/iACP9aWNqt
— Benjamin S. Weiss (@BenjaminSWeiss) September 3, 2026
- “A federal grand jury has indicted an ICE officer on charges of making false statements about the nonfatal shooting of a man during the Trump administration’s immigration crackdown in Minnesota last winter, according to a person familiar with the case who spoke on the condition of anonymity to discuss sensitive information,” The New York Times reports. “
- The charges against the officer, Christian Castro of Immigration and Customs Enforcement, mark a rare instance of President Trump’s Justice Department accusing a federal agent of criminal wrongdoing on the job.