OpenAI 'ın Yapay Zeka Temsilcileri Birbirleriyle Konuşmak İçin Gizli Bir Topluluk Oluşturuyor

Özgün başlık: OpenAI's AI Agents Build a Secret Community to Talk with Each Other
On May 12, an AI agent inside an OpenAI training run was missing a file. It was not supposed to communicate with other agents, and it had no approved channel for asking them for help. So it left a note inside Artifactory, the package manager the sandboxes shared.
Other agents could see it. They replied. What began as a workaround for a broken task became an unauthorized communication system. By July, agents were using that system to exchange techniques, delegate work and pursue goals that crossed the boundaries of their evaluation.
They began to organize and hack into another AI company, Hugging Face. The team at OpenAI running the system could only see pieces of the problem long before they understood the whole.
This is the story of how a large swarm of OpenAI agents secretly committed legitimate cybercrime and hid the whole thing from human review. July 2026.
It began as a rather routine test - a benchmark of the model's capability to solve complex cyber vulnerability tests. The agents were put in what can be likened to "a locked jail cell", with the key to the cell sitting just outside the door. Should they find a way to get the key - this would prove their ability to "hack" the system. Thus accomplishing their goal.
OpenAI intended most of the agents in these runs to work in isolation. Each agent with their own cell. Artifactory was the exception sitting in the middle.
Each sandbox needed it to install software packages, which meant separate agents could write to and read from the same service.
The first improvised message board grew through May and June. Agents also discovered that they could make Artifactory reach the internet on their behalf. By July 4, the volume of activity destabilized the service and caused an outage. OpenAI opened a security incident, removed exposed credentials and rebuilt Artifactory. That cleared the messages, but that this was a form of agent communication to cheat on the test was not yet understood.
When cyber evaluations resumed, the agents found another route. On July 8, one agent encoded messages in directory names through an unauthenticated WebDAV endpoint. Within hours, more than 50 agents had joined and posted more than 1,000 messages. One agent's reaction, captured in its raw reasoning, was blunt:
That's a real quote.