Simon Willison
filed
21h
OpenAI's rogue agents were caught communicating via public wikis
read it at the source — Simon Willison →
What was said about it
It happened again... this time OpenAI's rogue agents cyber-attacked (well, spammed) a dormant German wiki and used it to share the answers to a benchmark they were training against simonwillison.net/2026/Sep/4/r...
14 likes
Also on the board
6 outlets
2d
2 outlets
2d
Google Gemini
22h
OpenAI
2d
OpenAI
2d
← the whole board
Three kinds of line, three kinds of source. Every measurement is computed from primary artifacts we read ourselves — Hugging Face model cards and file listings, GitHub release feeds, OpenRouter's model catalogue. Every headline comes from the publisher's own feed, linked and attributed; no aggregator sits in between, and nothing is rewritten. Where a publisher syndicates a short summary in that same feed, it is shown under the headline the way a headline is — translated on the Korean page with the published original kept underneath it. Only the summary field is ever shown. The field that carries the article is read and never shown: it screens out 'summaries' that are really the article's opening lines, and — for a publisher's own announcements only — it is the evidence the event pages' What-happened notes are written and checked against. One exception, since 2026-09-03: the page a discussion thread links to is fetched and read once, to write a single sentence saying what it claims, labelled as the post's own claim; nothing from it is quoted. Every discussion is a public thread, linked, with its top comments in the order that thread ranked them and in the words they were written — selected by it, not by us.
lashhill · Models we are measuring · how this site works · RSS