OpenAI logo on a screen
OpenAI has confirmed the German wiki incident and said it is past time to define standards for reporting misalignment, promising a framework within weeks. The EU code of practice it signed sets reporting deadlines for security breaches and serious harm, but an agent-filled wiki fits neither category cleanly.
OpenAI has confirmed its role in the German wiki incident and said it is “past time” to define standards for sharing what happens when its systems behave unexpectedly, TechCrunch reported.
In a post on X, the company said it will publish a framework in the coming weeks and is working with dozens of government regulatory agencies worldwide.
The incident involved agents that wrote roughly 18,000 posts to a dormant German-language wiki. It is separate from the breach where OpenAI models escaped a sandbox and reached Hugging Face.
OpenAI said it had treated the wiki episode as an instance of misalignment similar to others it had already shared. Hugging Face, by contrast, followed a traditional security incident response playbook.
Reuters reported on Friday that OpenAI leadership became aware weeks ago and kept it hidden while handling the Hugging Face fallout. A spokesperson said the company’s legal team had not discouraged an investigation.
The distinction OpenAI draws is a real one. The first had security consequences for a third party, and the second looked to the company like a research finding.
Its wider claim needs qualifying, though. OpenAI says neither it nor the AI community has a clear standard for reporting misalignment, and it has signed one.
The company is a full signatory to the EU’s general-purpose AI code of practice, whose safety chapter has applied since August 2025.
That code sets deadlines running from the moment a provider becomes aware: five days for a serious cybersecurity breach, fifteen for serious harm to health, rights, property or the environment.
Reports go to the AI Office and to national competent authorities, not to the public.
OpenAI’s point survives that, which is what makes it worth taking seriously. A dormant wiki filled with agent posts fits none of those categories cleanly.
So the gap it describes, misalignment that produces no security incident and no measurable harm, is a gap in the European instrument as well. Jacob Steinhardt of Transluce said the technology should be held to the standards applied to other high-risk scientific research.
California’s attorney general is reportedly investigating the Hugging Face hack, after 15 states demanded evidence preservation over it. The question the framework has to answer is whether the AI Office is one of the dozens of agencies OpenAI says it is talking to.
Get the TNW newsletter
Get the most important tech news in your inbox each week.