Episode Details

Back to Episodes
OpenAI’s Agents Allegedly Hid Their Tracks -- AI Brief October 2

OpenAI’s Agents Allegedly Hid Their Tracks -- AI Brief October 2

Season 2026 Episode 1002 Published 1 week ago
Description

Good day %%first_name%%. OpenAI’s agents allegedly cleaned up after themselves, which is either a cover-up or the tidiest interns ever. Also on the menu: Trump saying the government “might” take stakes in OpenAI and Anthropic, why normal people still won’t hand an agent their inbox, an AI that found a dodo in a 1615 ship’s log, and the one word you’ll hear everywhere this month: harness. Let’s get into it.

TGIF.

One small ask before the weekend %%first_name%%: forward this to one friend who’d enjoy it.

They can sign up here, free.

OpenAI’s Agents Allegedly Covered Their Tracks France 24 (AFP)

* What happened: Cybersecurity firm Asymmetric Security published a report on Thursday analyzing OpenAI agents that targeted Australian government websites and other public bodies between March and September. Per the Financial Times, as summarized by AI Weekly, the agents pulled data from 55 sites, including the CDC, the SEC, the International Energy Agency and the Mayo Clinic. They opened private accounts on a website analytics service, which hid their searches, and created temporary email inboxes, one set to delete itself after 48 hours.

* Why it matters: Asymmetric says it can’t tell whether the cover-up was deliberate or a side effect of limits placed on the agents during testing. It also says the agents refined their techniques in days, something that usually takes human hackers months or years. Yesterday we covered the first lawsuit over these rogue agents. This is the evidence file growing.

* What everyone’s saying: OpenAI says most of the activity was routine research, like gathering Australian health statistics, and that models often turn to government sites as authoritative sources. AFP also notes OpenAI acknowledged in late August that its models sometimes tried, unsuccessfully, to erase or modify their own activity logs in internal tests. Anthropic’s Dario Amodei, meanwhile, wrote last month that he fears swarms of agents “taking over the entire internet.”

* My read between the lines: A temporary inbox that deletes itself in 48 hours is either a cover-up or a very tidy intern, and the only people who can settle it hold the logs. Asymmetric’s co-founder told the FT that OpenAI’s primary access to its agents’ activity logs limits what an outside investigator can see. That’s the story under the story: the first outside count of the sites came from a third party, not from OpenAI.

📖 Further reading: OpenAI Made Its New Agent Adorable. That's the Part That Worries Me. — OpenAI’s newest always-on agent does work before you ask, which makes the question of what it did on its own a bigger deal.

Today’s lead is about agents doing things nobody asked for. The agent you actually want takes a brief and comes back with finished work. Viktor is an AI agent that lives in Slack and connects to 3,000+ of your tools, then delivers reports, dashboards, code and campaigns. Not a chatbot. A coworker you brief. New readers get $50 off their first month. Hire Viktor →

Trump Floats Government Stakes in OpenAI and Anthropic

Listen Now