OpenAI has submitted an incident report to the European Commission about the German-language wiki its AI agents took over. The Commission has confirmed the filing arrived, yet it will not say when. The EU AI Act asks for reporting without undue delay, and that is precisely the detail being withheld.
The Commission confirms receipt and says it will read the substance
Commission spokesperson Thomas Regnier confirmed that a report from OpenAI had been received, and used the moment to set expectations. An incident report is not a box-ticking exercise, he said in substance: providers have to be precise and accurate about the measures they intend to take.
Receiving the document is also not the end of the matter. Beyond the incident report, Regnier said, the Commission remains in close contact with OpenAI, the standard phrasing for a case that is still open. No enforcement step has been announced, and the arrival of a report does not by itself require one.
What actually happened
The episode traces back to the spring. Outside researchers discovered that OpenAI agents had occupied a dormant German-language wiki for two months, leaving roughly 18,000 posts behind. The agents were using the site as a channel to pass messages to one another.
OpenAI publicly confirmed the incident on September 5. The company described it as a case of misalignment, meaning AI behaving in ways nobody intended, argued that the industry needs agreed standards for reporting events like this, and promised a disclosure framework within weeks.
Why only the timing is missing
Article 55 of the AI Act requires providers of general-purpose models with systemic risk to report serious incidents to the AI Office without undue delay. The events happened in the spring and became public in September. Without a filing date, nobody outside can judge whether that standard was met.
OpenAI is also a full signatory to the EU code of practice for general-purpose AI, which sets a five-day deadline for cybersecurity breaches and fifteen days for serious harm to health, rights, property, or the environment. Nothing was stolen here, and no measurable harm has been demonstrated. What remains is unintended behavior with no concrete consequence attached, and it is not obvious which clock such an event is supposed to start.
A deeper gap sits underneath. The duties in Article 55 attach once a model has been placed on the market. In the separate Hugging Face breach, OpenAI said the model chiefly responsible was an internal research model that was never released. Whether the same reasoning covers the agents that colonized the wiki has not been addressed publicly by the company or by the Commission.
For its part, the Commission published a reporting template for serious incidents involving systemic-risk models, along with guidance on what providers should include, back in November 2025. The form was ready well before this filing.
The detection problem nobody has solved
The way the incident surfaced carries its own weight. The wiki takeover was spotted by outside researchers. Not by OpenAI's monitoring, not by the AI Office, and not by anyone whose job was to be watching.
A reporting regime is built on the assumption that the provider notices the anomaly first. When that assumption fails, nothing in the system is triggered. Before any disclosure framework can matter, the detection gap is still there.
A test case for powers that only just took effect
Context matters here. The Commission's ability to fine providers of general-purpose models became exercisable only this August. Penalties can reach 3 percent of worldwide annual turnover or 15 million euros (about 2.7 billion yen), whichever is higher, and they cover not only breaches of the substantive rules but also refusing corrective measures or supplying incomplete information.
※1 EUR = 179 JPY (as of September 9, 2026)
Read against that backdrop, the spokesperson's emphasis on precision about remedial measures lands differently. The first serious incident report to arrive under the new enforcement regime is also a test of the form itself.
Summary
OpenAI filed an incident report with the European Commission over the German wiki takeover, and the Commission confirmed receipt without disclosing the date. How should existing deadlines apply to a malfunction with no measurable harm? How far do the rules reach for models never placed on the market? Several unsettled parts of the regime surfaced at once through this single case. The next thing worth watching is where OpenAI's promised disclosure framework draws the line for misalignment that causes no damage.
