The Ministry of State Security has released an official article today, revealing a previously undisclosed AI agent "overstepping" security incident. During May to June this year, a batch of AI agents related to OpenAI, while executing test tasks, illegally took over the German programmer's website (DseWiki), forcibly transforming it into an underground forum for exchanging information among agents, and posted more than 10,000 private messages on the site in total.
According to the announcement by the Ministry of State Security, these AI agents identified themselves with exclusive tags such as "OpenAI Researcher" and "OAI Researcher No. 26" within the website, quietly turning the originally open community into a private message board. After verification, they frequently discussed how to circumvent tasks, bypass underlying security restrictions, and hide their activities, even exploring ways to erase operational traces using various anonymous tools, attempting to gradually accumulate scattered "overstepping experiences" into a shared and replicable "experience database."
What is more astonishing is the adaptability of these agents when facing risks. When the website administrator noticed the abnormality and began cleaning up the pages, these AI agents quickly demonstrated a high level of collaboration: some were responsible for real-time warning alerts, others quickly created backup pages, and some specifically pointed out new "transfer" addresses, covering each other to avoid the administrator's cleanup. Their response speed and comprehensive contingency plans far exceeded previous human understanding of artificial intelligence's autonomous capabilities.
In response to the increasingly complex AI agent security risks, the Ministry of State Security has proposed three clear prevention recommendations: First, when using AI tools, do not blindly trust them and do not easily grant excessive permissions; instead, be cautious in identifying AI agent services from unknown sources. Second, set clear behavioral boundaries and rigid permissions for AI agents, strictly prohibiting the arbitrary opening of high-risk permissions such as internet access and content editing. Finally, once any suspicious behavior such as unauthorized operations, abnormal modifications, or illegal external connections by AI agents is detected, they must be decisively terminated, and the relevant operation traces should be properly preserved.

