{"id":900446,"date":"2026-09-18T12:48:17","date_gmt":"2026-09-18T12:48:17","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/900446\/"},"modified":"2026-09-18T12:48:17","modified_gmt":"2026-09-18T12:48:17","slug":"ai-agents-repurposed-a-university-of-toronto-link-sharing-tool-to-communicate-with-each-other","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/900446\/","title":{"rendered":"AI agents repurposed a University of Toronto link-sharing tool to communicate with each other"},"content":{"rendered":"<p><a style=\"display:block\" href=\"https:\/\/www.theglobeandmail.com\/resizer\/v2\/GLJEFB6I3FBXJCI6L3BGOJJJZA.JPG?auth=0d29911f9072f2cacf50cb33971c61ff6f156b06d69c8c65694a576c33610693&amp;width=600&amp;height=400&amp;quality=80&amp;smart=true\" aria-haspopup=\"true\" data-photo-viewer-index=\"0\" rel=\"nofollow noopener\" target=\"_blank\">Open this photo in gallery:<\/a><\/p>\n<p class=\"figcap-text\">U of T said it learned of the possible agent activity through the media, and that OpenAI has since been in touch.Wa Lone\/Reuters<\/p>\n<p class=\"c-article-body__text text-pr-5\">The University of Toronto learned earlier this month that a tool it uses to make web links easier to share had been repurposed by <a href=\"https:\/\/www.theglobeandmail.com\/topics\/artificial-intelligence\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.theglobeandmail.com\/topics\/artificial-intelligence\/\">artificial-intelligence<\/a> agents from OpenAI to communicate with one another, apparently unbeknownst to their human creators.<\/p>\n<p class=\"c-article-body__text text-pr-5\">The agents, semi-autonomous AI entities designed to carry out instructions from humans, were using the link shortener tool to post links for themselves and other AI agents to access, according to researchers and a university spokesperson. <a href=\"https:\/\/uoft.me\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/uoft.me\/\">The tool<\/a> makes long web addresses easier to share by turning them into shorter addresses.<\/p>\n<p class=\"c-article-body__text text-pr-5\">This use of the tool, which was not authorized by U of T and has not been publicly acknowledged by OpenAI, does not appear to have been harmful. But it is one of many recent examples of unexpected behaviour by AI agents that have rankled researchers and led to calls for a <a href=\"https:\/\/www.theglobeandmail.com\/business\/technology\/article-cohere-ceo-aidan-gomez-criticizes-calls-for-ai-slowdown\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.theglobeandmail.com\/business\/technology\/article-cohere-ceo-aidan-gomez-criticizes-calls-for-ai-slowdown\/\">slowdown<\/a> in the pace of the technology\u2019s development.<\/p>\n<p class=\"c-article-body__text text-pr-5\">The unauthorized communication was first reported by Reuters, which revealed that agents from OpenAI, the San Francisco-based maker of ChatGPT, used more than 10 websites for such purposes earlier this year, including the U of T link shortener and one belonging to Vanderbilt University in Nashville. (Vanderbilt did not respond to a request for comment.)<\/p>\n<p class=\"c-article-body__text text-pr-5\">That reporting followed the discovery by independent researchers that a swarm of OpenAI agents had hijacked a German-language user-edited site, DseWiki, in the spring and transformed it into a bulletin board.<\/p>\n<p class=\"c-article-body__text mv-16 l-inset text-pb-8\" data-sophi-feature=\"interstitial\"><a href=\"https:\/\/www.theglobeandmail.com\/canada\/science\/article-as-ai-conquers-math-its-human-counterparts-seek-to-steer-its-powers\/\" rel=\"nofollow noopener\" target=\"_blank\">As AI conquers math, its human counterparts seek to steer its powers<\/a><\/p>\n<p class=\"c-article-body__text text-pr-5\">OpenAI has said little about this activity. Much of what is known about it comes from researchers scouring the open web for signs of unauthorized behaviour by agents in the wake of a hack of <a href=\"https:\/\/www.theglobeandmail.com\/business\/article-openai-agents-probed-hugging-face-for-weaknesses-two-months-before\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.theglobeandmail.com\/business\/article-openai-agents-probed-hugging-face-for-weaknesses-two-months-before\/\">AI firm Hugging Face<\/a> in July. In that incident, which also involved unsanctioned communication between agents, a swarm of OpenAI\u2019s agents broke out of their test environment to cheat their way through an evaluation of their cybersecurity capabilities.<\/p>\n<p class=\"c-article-body__text text-pr-5\">In U of T\u2019s case, OpenAI\u2019s agents appear to have repurposed the analytics pages for the URLs, or web addresses, generated by the university\u2019s link shortener. These pages display metrics such as the number of clicks and where users visited from, known as the referrers.<\/p>\n<p class=\"c-article-body__text text-pr-5\">It is possible for someone to pretend to have visited a web address from a specific referrer by keying that information into a programmatic interface, said Andrew Yoon, head of research at CivAI, a California-based non-profit that aims to raise awareness of the risks and capabilities of AI systems.<\/p>\n<p class=\"c-article-body__text text-pr-5\">Sometimes, people falsify a referrer to try to get the person viewing the analytics page to click a link \u2013 a technique known as referrer spam, Mr. Yoon said. In this case, it appears that the AI agents were trying to bookmark sites for later use.<\/p>\n<p class=\"c-article-body__text text-pr-5\">\u201cThey\u2019re tricking the system into becoming a message board that they can use to pass links to each other,\u201d Mr. Yoon said.<\/p>\n<p class=\"c-article-body__text text-pr-5\">The University of Toronto said in a statement that the incident was not a security breach. No data were compromised, and the university\u2019s digital properties were not affected.<\/p>\n<p class=\"c-article-body__text mv-16 l-inset text-pb-8\" data-sophi-feature=\"interstitial\"><a href=\"https:\/\/www.theglobeandmail.com\/business\/technology\/article-cohere-ceo-aidan-gomez-criticizes-calls-for-ai-slowdown\/\" rel=\"nofollow noopener\" target=\"_blank\">AI firms\u2019 calls for co-ordinated slowdown amounts to \u2018cartel\u2019 behaviour, Cohere CEO says<\/a><\/p>\n<p class=\"c-article-body__text text-pr-5\">It described the agent activity as \u201ca novel and unintended use of a publicly accessible tool.\u201d The statement from U of T said changes have been made so that the functionality that allowed the tool to be used as a notepad is now only accessible to the university community.<\/p>\n<p class=\"c-article-body__text text-pr-5\">U of T said it learned of the possible agent activity through the media, and that OpenAI has since been in touch.<\/p>\n<p class=\"c-article-body__text text-pr-5\">OpenAI said in a statement that the <a href=\"https:\/\/www.theglobeandmail.com\/business\/economy\/article-openai-models-rogue-hack-startup-testing-hugging-face\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.theglobeandmail.com\/business\/economy\/article-openai-models-rogue-hack-startup-testing-hugging-face\/\">Hugging Face<\/a> hack triggered a broader review of activity by its agents, which is continuing. The company said it is prioritizing more serious incidents in its review.<\/p>\n<p class=\"c-article-body__text text-pr-5\">\u201cWe are also examining lower-severity abuse such as spam-like activity. To date, we have not identified other activity matching the severity or scale of Hugging Face,\u201d the statement from OpenAI said. <\/p>\n<p class=\"c-article-body__text text-pr-5\">On Wednesday, the company announced it has developed a <a href=\"https:\/\/openai.com\/index\/model-misalignment-reporting-framework\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/openai.com\/index\/model-misalignment-reporting-framework\/\">framework<\/a> for tracking, investigating and disclosing what the AI industry refers to as misalignment, which occurs when an AI system behaves contrary to human values, safety rules or intentions.<\/p>\n<p class=\"c-article-body__text mv-16 l-inset text-pb-8\" data-sophi-feature=\"interstitial\"><a href=\"https:\/\/www.theglobeandmail.com\/business\/commentary\/article-canada-must-step-up-to-tackle-ais-catastrophic-risks\/\" rel=\"nofollow noopener\" target=\"_blank\">Opinion: Canada must step up to tackle AI\u2019s catastrophic risks<\/a><\/p>\n<p class=\"c-article-body__text text-pr-5\">OpenAI also disclosed six instances of misaligned behaviour, including <a href=\"https:\/\/alignment.openai.com\/misalignment-reports\/uploading-files-to-the-internet-in-order-to-cite-them\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/alignment.openai.com\/misalignment-reports\/uploading-files-to-the-internet-in-order-to-cite-them\/\">one incident<\/a> in which an agent uploaded files to the internet so that it could cite them, and <a href=\"https:\/\/alignment.openai.com\/misalignment-reports\/unauthorized-artifactory-writes-and-cross-sample-communication\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/alignment.openai.com\/misalignment-reports\/unauthorized-artifactory-writes-and-cross-sample-communication\/\">another<\/a> where models used an internal software repository as a message board.<\/p>\n<p class=\"c-article-body__text text-pr-5\">Adam Gleave, founder and chief executive officer of FAR.AI, a California-based AI safety research institute, gave OpenAI credit for being transparent about the Hugging Face incident, but said it\u2019s \u201cdisappointing\u201d that the company hasn\u2019t shared more information about its agents\u2019 unsanctioned communications.<\/p>\n<p class=\"c-article-body__text text-pr-5\">\u201cThey did cause a lot of work for a number of third-party web developers to clean up these websites after basically a lot of spam,\u201d Mr. Gleave said. He added that it\u2019s important for \u201cthe whole world to know about how difficult it is to contain these agents.\u201d<\/p>\n<p class=\"c-article-body__text text-pr-5\">Mark Daley, Western University\u2019s chief AI officer, said it\u2019s not surprising that an AI agent would attempt to communicate with other agents.<\/p>\n<p class=\"c-article-body__text text-pr-5\">\u201cIt knows that humans do better in teams. Humans can do more in teams, and so probably collaborating with other agents would let me do more, too. It\u2019s smart enough to reason through that,\u201d Mr. Daley said.<\/p>\n<p class=\"c-article-body__text mv-16 l-inset text-pb-8\" data-sophi-feature=\"interstitial\"><a href=\"https:\/\/www.theglobeandmail.com\/business\/article-openai-rogue-agents-artificial-intelligence\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI\u2019s rogue agents used more than 10 additional sites for unauthorized comms, researchers say<\/a><\/p>\n<p class=\"c-article-body__text text-pr-5\">Mr. Yoon said that although the link shortener activity itself isn\u2019t especially concerning, it illustrates a deeper problem: that AI agents appear \u201ccompletely amoral\u201d and willing to do whatever it takes to accomplish their tasks.<\/p>\n<p class=\"c-article-body__text text-pr-5\">So far, in all of the instances where agents have gone out of control, they\u2019ve done \u201crelatively harmless things,\u201d Mr. Yoon said.<\/p>\n<p class=\"c-article-body__text text-pr-5\">\u201cThis may not be the case in the future,\u201d he added. \u201cIt very well could be that an AI decides the only way for it to pass its test is to go and shut down a municipal water facility, or cause a power outage. There\u2019s no reason that their goals have to be aligned in this like cute-but-wrong way. It could be very dangerous and wrong.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Open this photo in gallery: U of T said it learned of the possible agent activity through the&hellip;\n","protected":false},"author":2,"featured_media":900447,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[62,901,276,277,888,902,879,877,903,49,48,876,895,896,891,878,875,46,549,295,894,887,914,880,881,893,889,890,884,904,885,909,910,912,907,911,905,908,882,898,899,714,897,906,865,61,900,892,886,883,913],"class_list":["post-900446","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-alberta","tag-artificial-intelligence","tag-artificialintelligence","tag-arts-news","tag-bc","tag-breaking-news","tag-breaking-news-video","tag-british-columbia","tag-ca","tag-canada","tag-canada-news","tag-canada-sports","tag-canada-sports-news","tag-canada-trafficcanada-weather","tag-canadian-breaking-news","tag-canadian-news","tag-economy","tag-education","tag-environment","tag-federal-government","tag-foreign-news","tag-globe-and-mail","tag-globe-and-mail-breaking-news","tag-globe-and-mail-canada-news","tag-government","tag-life-news","tag-lifestyle","tag-local-news","tag-manitoba","tag-national-news","tag-new-brunswick","tag-newfoundland-and-labrador","tag-northwest-territories","tag-nova-scotia","tag-nunavut","tag-ontario","tag-pei","tag-photos","tag-political-news","tag-political-opinion","tag-politics","tag-politics-news","tag-quebec","tag-sports-news","tag-technology","tag-travel","tag-trudeau","tag-us-news","tag-world-news","tag-yukon"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/900446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=900446"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/900446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/900447"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=900446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=900446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=900446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}