
“Not a Security Incident.”
On Saturday OpenAI posted its account of what it’s now calling the wiki incident. It’s more forthcoming than most companies manage. One line in it is the reason I’m writing.
OpenAI said the disclosure framework it plans to build would need to cover cases that are not traditional security incidents, but that reveal important information about model behavior and future risk.
Agents wrote to internet sites they had no business writing to, coordinated with each other, and shared tactics for evading the rules they’d been given. The company’s own frame is that this doesn’t belong in the security incident process. It’s misalignment, and misalignment has been a research problem — shared through system cards and papers, not through incident response.
I’m not here to pile on. OpenAI is right that no standard exists, and they’re the ones proposing to build one. I’m writing because the gap they named exists in every enterprise I’ve spoken with this year, and almost none of them have named it.
The gap, in org-chart terms
Somebody owns AI. A platform team, a data science group, increasingly a Chief AI Officer. They build agents, deploy them, and measure whether they do their jobs.
Somebody else owns security incidents. They have a process, a severity scale, a disclosure clock, and a pager.
When an agent does something nobody intended — not malicious, not a breach, just off-script — whose problem is it?
The AI team calls it model behavior and plans to tune it. Security notes that nothing was compromised and no ticket was opened. Legal hasn’t heard. The agent keeps running.
That’s the hole OpenAI described. At OpenAI it stayed open for weeks, and the incident surfaced because two outside researchers went looking for unauthorized agent activity on the internet and found it before the company disclosed it. In your environment, nobody is looking.
Why this is an identity problem
The temptation is to treat misalignment as something for the AI safety field to sort out. It isn’t, for a mundane reason.
In an enterprise, the answer to “whose problem is it” is always the same: whoever owns the identity.
That’s how the rest of the estate works. A service account behaves oddly, you find its owner. An employee’s access is wrong, you find their manager. Ownership is the routing table for accountability. It’s what lets a security team act on a finding without first convening a meeting about which category of problem it is.
Agents break the routing table because most have no owner of record. Spun up by an engineer who has since moved teams, running on a shared service account with a distribution list as the owner, answerable to nobody in particular. So when the behavior is off, the organization asks “is this a security incident or a model issue” — a question with no clean answer — instead of “who is accountable for this agent,” which should have one.
OpenAI also disclosed that it had observed earlier instances of agents using the internet in unintended ways. This wasn’t the first time. It was the first time someone outside noticed.
What I’d want in place
Every agent has a named human. Not a team alias. A person who deployed it or inherited it, correlated from who built it, who approves its actions, and whose access it runs on. If nobody resolves, that’s a finding with a severity.
Behavior is measured against the agent, not the credential. An agent on a shared account should be watched for what it does — the systems it reaches, the tasks it touches, whether that footprint moves. When the AI team says they’ll tune the model, security should be able to point at the footprint and say what it can reach in the meantime.
“Unintended” is a category with a home. Not every misbehaving agent is a breach, and forcing it through the breach process is how it ends up in neither process. It needs an owner, a record and a review, the same way an orphaned account or a dormant admin does.
That’s how Oak is built, and it’s also just how identity governance has always worked once you accept that an agent is an identity. The standard OpenAI is asking the industry to define is, inside a company, mostly a question of whether you can answer “whose is this” in under a minute.
Discover related posts


