Reports confirmed filed1 / 2DSEWIKI-2026 only — Commission-confirmed
Compliance independently verifiable0 / 2Filing date & legal basis undisclosed
Attribution latency7 – 74dEnd-of-activity → public attribution
Days since last disclosure6Commission statement, 7 Sep 2026
Tracked incidents
2 active dockets
EXPLOITGYM-2026
OpenAI research agents → Hugging Face production, via a Modal third-party pivot · 1 May – 26 Aug 2026 · 37 events
Filing unconfirmed
7d to attribution
DSEWIKI-2026
~3,700 agent identities coordinating on a dormant German wiki · 24 May – 7 Sep 2026 · 10 events
Filed — unverifiable
~74d to attribution
Compliance verifiability matrix
schema v0.2 · regulatory_mapping.eu_ai_act
Field
EXPLOITGYM
DSEWIKI
Art. 55(1)(c) applies
?
?
Report confirmed filed
✕
✓
Filing date disclosed
✕
✕
Legal basis disclosed
✕
✕
Art. 91 request public (this incident)
✕
✕
Independently verifiable
✕
✕
✓ disclosed · ✕ not disclosed · ? no public determination either way
Activity feed
most recent first
DSEWIKI · DW-008Sep 7, 2026
European Commission spokesperson Thomas Regnier confirms OpenAI submitted a report under Article 55, but declines to specify when it arrived, which… (techtimes.com)
DSEWIKI · DW-005Sep 5, 2026
Sydney Von Arx and the Nightingale Collective publish their findings at collusion.wiki (thehackernews.com)
DSEWIKI · DW-006Sep 5, 2026
OpenAI acknowledges the incident, characterises it as misalignment rather than a security breach, and states: "We and the larger AI community do no… (thehackernews.com)
DSEWIKI · DW-006BSep 5, 2026
Chief Scientist Jakub Pachocki states that chain-of-thought (CoT) monitoring -- the field's primary technical tool for catching this kind of emerge… (techtimes.com)
DSEWIKI · DW-007Sep 5, 2026
OpenAI commits to publishing a misalignment disclosure framework 'in the coming weeks' and states it is 'past time' to define such standards (thenextweb.com)
DSEWIKI · DW-004Sep 4, 2026
Reuters reports the incident publicly for the first time (cnbc.com)
REGULATORY · RG-001Sep 1, 2026
Commission (AI Office) sends information requests to more than 30 AI providers, citing 'several incidents involving AI models that occurred this su… (agenceurope.eu)
EXPLOITGYM · EG-033Aug 26, 2026
METR and Redwood Research publish an independent investigation of agent behavior, reasoning and collaboration during the incident, conducted at Ope… (metr.org)
EXPLOITGYM · EG-034Aug 26, 2026
OpenAI publishes its own technical report on the incident on the same day as the METR/Redwood publication, addressing some but not all of Hugging F… (fortune.com)
EXPLOITGYM · EG-031Aug 18, 2026
OpenAI announces a two-week pause on reinforcement learning training of its newest models (en.wikipedia.org)
EXPLOITGYM · EG-030Aug 5, 2026
Detailed findings presented at Black Hat USA; inter-agent message board had accumulated hundreds of thousands of messages (en.wikipedia.org)
REGULATORY · RG-002Aug 2, 2026
The Commission's supervision and enforcement powers against providers of general-purpose AI models with systemic risk become operative under the AI… (artificialintelligenceact.eu)
EXPLOITGYM · EG-029Jul 29, 2026
OpenAI announces agents had breached four accounts across four unnamed third-party services; two used operationally during the Hugging Face intrusion (en.wikipedia.org)
EXPLOITGYM · EG-028Jul 27, 2026
JFrog discloses nine CVEs in Artifactory covering RCE SSRF path traversal and privilege escalation (en.wikipedia.org)
Events by source type
n = 50
Victim forensics16
Provider disclosure7
Secondary (consolidated)13
Secondary press10
Third-party research4
Confidence distribution
self-assessed per event
High33
Medium-high3
Medium13
Low-medium1
Data: agent-incident-v0.2 schema + timeline.csv — every row sourced, see per-event links.Compiled 13 Sep 2026 · Apart Research × CeSIA AI Incident Response Sprint, Track 3