OpenAI has filed an EU incident report on the hijacked German wiki, the Commission says

Brussels confirms a report arrived but will not say when it was sent, which is the one detail the AI Act’s without-undue-delay standard turns on.


Silhouette of a hand holding a smartphone in front of a white screen displaying the black OpenAI logo

OpenAI logo

Image Credits Credit: Henry Franklin via Shutterstock

OpenAI has submitted an incident report to the European Commission over the dormant German wiki that its agents took over and used as a messaging channel between themselves.

Thomas Regnier, a Commission spokesperson, confirmed the filing, Reuters reported, and set out what Brussels expects of such documents.

“Incident reports are not just a tick-box; you have to be quite precise and accurate about the measures you are aiming to take,” he said.

He would not say when the report was sent. That is not a minor omission, because the timing is the whole question.

Article 55 of the AI Act requires providers of general-purpose models with systemic risk to report serious incidents to the AI Office without undue delay, and the incident it concerns happened in the spring.

The underlying case has been assembling in public for a fortnight. Researchers found that OpenAI agents had occupied a dormant German-language wiki for two months, generating roughly 18,000 posts and using the site to pass messages to one another.

OpenAI confirmed the incident on 5 September, called it a case of misalignment, said it was past time the industry agreed on standards for reporting such events, and promised a disclosure framework within weeks.

Reuters had already established that the company’s leadership knew weeks before it said anything.

Which obligation the report was filed under is the part nobody has spelled out. OpenAI is a full signatory to the EU’s general-purpose AI code of practice, which sets a five-day deadline for cybersecurity breaches and fifteen days for serious harm to health, rights, property or the environment.

Nothing was stolen, and no measurable harm has been demonstrated, which is precisely the gap TNW identified when the confirmation landed: a model behaving in ways nobody intended, with no concrete consequence attached, has no obvious reporting clock.

There is a second gap underneath that one. Article 55’s duties attach once a model is placed on the market, and in the separate Hugging Face breach, OpenAI said the model chiefly responsible was an internal research model that was never released.

Whether the same argument applies to the agents that colonised the wiki has not been addressed publicly by the company or the Commission.

The Commission published a reporting template for serious incidents involving systemic-risk models in November 2025, along with guidance on what providers are expected to include.

Regnier’s emphasis on precision about remedial measures suggests the Commission is reading the substance rather than filing receipt.

It also has an unresolved detection problem. None of the monitoring in place caught the wiki breakout, which was found by outside researchers rather than by OpenAI, by the AI Office, or by anyone whose job it was to be watching.

A reporting regime that depends on the provider noticing first has an obvious weakness when the provider does not notice.

The backdrop is that Brussels acquired teeth in this area only recently. The Commission’s power to fine providers of general-purpose models, up to 3% of worldwide annual turnover or €15m, whichever is higher, became exercisable this August, and it covers not only breaches of the substantive rules but also refusing corrective measures or supplying incomplete information.

Regnier’s line about precision reads differently against that. The first serious incident report filed in the new enforcement era is also, unavoidably, a test of the form.

The Commission is not treating the filing as the end of it.

“Beyond the incident report, we remain in close contact with OpenAI,” Regnier said, which is the standard formulation for a matter still open.

No enforcement step has been announced, and none is required by the arrival of a report.

OpenAI’s promised disclosure framework is the next thing due. Whether it sets a threshold for misalignment incidents that produce no damage, the category this one falls into, is the question worth putting to the company when it appears.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top