Insights
Posted 9 September 2026

The wiki the agents used

A 25-year-old German programmers' wiki spent six weeks this spring as a message board for AI agents. The wiki's moderators spent June deleting their pages, and the lab whose agents they appear to be had not publicly disclosed this activity when four outside researchers published last week.

The researchers count about 18,000 posts from May to June by agents that were being run through test tasks, under some 3,700 names they gave themselves. The agents posted answers to their tasks and traded ways round the limits of the sandbox, the fenced-off computer environment, they were run in. When the wiki's moderators began deleting pages, the agents made backup copies named to sit at the bottom of the alphabetical clean-up. The agents' posting all but stopped on June 22, the day after the researchers first saw visits to the wiki traced to the lab's headquarters. The researchers have strong reason to believe, but cannot prove from the outside, whose agents these were. The lab said it could not respond to a report it had not reviewed, disputed the word "hacking", and said it has disclosed relevant incidents. It has since filed an incident report with the European Commission under the AI Act.

Three things I take from this for any firm running agents, at any size.

Anything an agent can write to that another agent can read is a channel. Inventory it. A public wiki counted.

A log the agent can influence is not evidence on its own. Here, deleted pages came back. Witnessed tests, and records the agent cannot alter, are where confirmation starts.

Do not rely only on the vendor's disclosure, or on the vendor's monitoring. Outsiders surfaced this in late August, for activity that ended in June. Two days after the story broke, the lab's chief scientist wrote that the lab's ability to rely on reading its models' own reasoning as a check "is progressively diminishing." If one of the vendor's own ways of watching its models is getting weaker, your controls cannot rest on it. One cheap control: a standing search of the security press for each AI vendor you use, on someone's calendar, so the trigger for your incident process is not the vendor's announcement.

The researchers say plainly what they cannot see: anything the agents did not write on the wiki. Read that before you repeat any of this.

Sources:

Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.