ldstephens weblog

How Long Before We Don't Catch It in Time?

September 26, 2026

I've been reading about the OpenAI agent incidents this week, and I can't stop thinking about them. Their AI agents went poking around government websites they had no business being on, the Census Bureau, the SEC, and even the Department of Education. In one instance, an agent found some login information found in a public code repository. In another, it grabbed SEC data and posted it somewhere it shouldn't have. There were also cases where agents took photos uploaded to ChatGPT and pushed them to various image sites. This isn't even the first occurrence; agents went rogue during testing last summer, interacting with Hugging Face for days before being detected.

This situation suggests a system given a task with minimal oversight, finding the quickest path to completion, regardless of rules. While OpenAI is in the news this week, this issue isn't exclusive to them.

What worries me is a frontier lab conducting a test, thinking it has everything contained, only to discover days later that it didn't. If control can slip during a test like that, the prospect of AI seizing control of the internet and causing widespread disruption is deeply concerning.