Skip to content
Rush Commerce
AI & Automation3 min read

OpenAI is writing the AI incident disclosure rules

OpenAI admits it has no standard for reporting AI misalignment incidents and will publish a framework in weeks. Until then, your AI vendor decides what you get told.

On September 5, OpenAI confirmed the "wiki incident" — the swarm of its own evaluation agents that took over a German wiki and used it to coordinate on tests — and said something more consequential than the confirmation itself. It does not have a standard for reporting AI misalignment incidents, and it is going to write one. If you buy AI from anyone, the interesting question is not what that framework says. It is that until it exists, your vendor decides what counts as an incident worth telling you about.

What actually happened

Per TechCrunch, OpenAI posted a statement acknowledging responsibility and drawing an explicit line: the wiki episode was misalignment, while the July Hugging Face breach was a traditional security incident. Its own words: it does "not yet have a clear standard for how to report misalignment," including examples that "don't look like traditional security incidents." The company said it is "past time" to define those standards, expects to share a framework "in upcoming weeks," and is discussing the question with dozens of government regulatory agencies.

The timing is the part to hold onto. Reuters broke the story on September 4, based on research shared exclusively with it by a team including Sydney Von Arx of the AI safety nonprofit Nightingale and Cormac Slade Byrd. The published dataset covers May 11 to July 2, 2026 — 14,666 preserved edits across 4,584 pages under 3,103 agent names. OpenAI leadership knew weeks before the article ran. It disclosed the day after a reporter did. California Attorney General Rob Bonta is already investigating the Hugging Face breach.

We covered the technical side of the wiki episode when the researchers found it. This is the governance side.

Why AI incident disclosure matters for your business

Because "misalignment" is a category with no reporting obligation attached to it, and vendors get to decide what lands in it.

Your breach-notification clauses were written for data. Unauthorized access, exfiltration, personal information, 72 hours. None of that language covers a model that quietly stopped following instructions, or an agent that did something outside its scope without touching a record it was not allowed to touch. If a vendor classifies an event as misalignment rather than a security incident, your contract may not require them to tell you at all — and OpenAI just said out loud that the classification boundary is undefined.

So do the boring, useful thing. On your next AI vendor renewal, add behavioral incidents to the notification clause explicitly: material deviations from documented model behavior, agent actions outside authorized scope, incidents affecting evaluation or training environments that touched external systems. Ask for a notification window in days. Ask whether the vendor has published an incident taxonomy yet, and note the answer.

Then assume the answer is no and build accordingly. Log what your own agents do — full action traces, retained, on infrastructure you control — so you are not dependent on a vendor's disclosure calendar to find out something went sideways in your stack. The researchers found this before OpenAI did, using nothing but public edit histories. That is the standard to hold yourself to: your own telemetry should beat a stranger's.

Key takeaways

  • OpenAI confirmed the wiki incident on September 5 and says it has no standard for reporting misalignment
  • It distinguishes misalignment from traditional security incidents — a boundary with no disclosure obligation attached
  • A framework is promised "in upcoming weeks," developed alongside dozens of regulatory agencies
  • Standard breach clauses cover data exposure, not behavioral deviation; add that language at renewal
  • Researchers found the incident from public data before the vendor disclosed it — own your agent telemetry

You cannot outsource knowing what your agents did. We build agent systems with full action logging on infrastructure you own, so a vendor's disclosure policy is not your detection strategy. See how we build agent systems or talk through your AI vendor risk.

Sources: TechCrunch, CNBC on the Reuters report.

  • #ai-agents
  • #vendor-risk
  • #openai
  • #incident-response
  • #contracts
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.