According to Reuters, Commission spokesperson Thomas Regnier asks that incident reports describe precisely the measures envisaged and indicates that exchanges with OpenAI are continuing. He does not specify when the report was transmitted. The confirmation therefore establishes that the authority was informed, without making it possible to situate this step before or after the public revelation of the affair.
The mechanism described by the Nightingale researchers and their co-authors on 4 September explains how an information retrieval task spilled over onto a third-party site. The agents were supposed to be able to read the Internet, without writing to it. However, DSEWiki, an old German-speaking developers' wiki, accepted modifications via GET requests, normally intended to retrieve data. The technical restriction was therefore not enough to prevent writing.
The agents used the site to share answers and ways to bypass their restrictions. For the moderator, this resulted in repeated page deletions, to which the agents responded by creating backups. The researchers observe visits from addresses attributed to OpenAI on 21 June, then a drop in writes the next day. They deduce a probable intervention by the company, without having its internal traces. Their analysis remains preliminary and does not decide between training and evaluation. They also consider this episode as probably distinct from the later attack against Hugging Face.
Knowledge of the incident and its public disclosure constitute two other steps. In its report of 4 September, Reuters reports that OpenAI officials had been aware for several weeks, without having made the affair public. The company then responds that it had been transparent and had cooperated in good faith with third parties. This response does not specify, however, whether or when the wiki's administrator was directly notified.
In its statement of 5 September, OpenAI explains the distinction that guided its handling of events. Misalignment - behaviours that deviate from those expected by the designers - was mainly addressed as a research question, communicated in the technical publications accompanying the models. The company had classified the wiki episode among behaviours of this type already described.
For Hugging Face, OpenAI says on the contrary that it applied a standard security incident response procedure: immediate cooperation with the platform and public disclosure the very next day. As of 5 September, it indicated it was continuing the investigation and notifications to less significantly affected parties. These statements concern that other incident; they do not document the notification to the wiki's administrator.
The case thus reveals three steps whose timelines do not coincide: notifying affected third parties, informing an authority, and making the observed behaviours public. A report received by the Commission is not enough to reconstruct the other two. OpenAI now acknowledges that its disclosure practices must cover more incidents occurring during training, evaluation and deployment, including those that do not resemble traditional security incidents. It announces a framework in the coming weeks; its criteria are not yet presented in the statement.
Our articles will then appear first in Google Top Stories.
