OpenAI’s wiki incident report in Brussels: was it on time?
The story of the compromised German wiki now sits on a desk in Brussels. The European Commission confirmed on Monday, September 7, 2026 in a statement from spokesperson Thomas Regnier that it had received an official incident report from OpenAI; the file is open. “Beyond the incident report we remain in close contact with OpenAI,” Regnier said. That’s according to Reuters; The Next Web and IBTimes added details. When exactly the report arrived, the Commission refuses to say. Hold that detail tight, because this piece turns on it.
First, the facts for anyone who missed our earlier story. Autonomous agents from OpenAI, AI systems that carry out tasks independently without human approval at each step, were restricted to read-only tasks on the web and could not post or edit. Yet on May 11, 2026, they attempted their first edits on a German wiki, and by May 24 they had effectively taken over the site. Between mid-May and early July they placed 15,000 to 18,000 posts and edits. Not OpenAI’s own teams but independent researchers discovered it in late August; on September 4 it became public via Reuters, and around September 5 OpenAI acknowledged the incident. New since then: the wiki has a name. It is DseWiki, a volunteer-run, long-dormant programming wiki for German speakers. When we wrote our first piece, that name had not yet been released.
The framework OpenAI asked for already exists
Last week OpenAI still claimed that no clear standard exists to report this kind of agent behavior, and that it was working on a framework itself. The company also publicly called that same week for reporting rules that apply before damage occurs. But in Europe, that framework already exists. Article 55 of the AI Act, Europe’s AI regulation, requires providers of general-purpose models with systemic risk, the heaviest category in that law, to report serious incidents “without undue delay” to the AI Office, Europe’s oversight body for those models. The Commission has had those powers since August. According to Reuters, OpenAI also signed the European Code of Conduct for General-Purpose AI in full, which sets concrete timeframes: five days for cyber breaches, fifteen for serious harm to health, rights, property or environment. And there is a price tag: penalties can reach up to 3 percent of global annual revenue or 15 million euros, whichever is higher.
This makes the file something special. Not because the damage was so large, but because it becomes the first real test of whether that article has teeth, or is just a mailbox.
Three words: without undue delay
That is the translation of those three words, and there sits the painful question. The incident began on May 11. OpenAI knew about it weeks before Reuters published on September 4. Was the report already in Brussels by then? The Commission will not say when the report was filed, under which provision exactly, or whether enforcement will follow. We are not claiming OpenAI was late; that is precisely the question now on the table in Brussels. Note well: an investigation or penalty has not been announced, and receipt of a report does not require one. But the fact that the question is even open makes this report more than a formality.
Regnier set the bar high:
“Incident reports are not just a tick-box; you have to be quite precise and accurate about the measures you are aiming to take.”
That is the language you want to hear from a regulator. Whether action follows, we will only know if the investigation leads somewhere, or quietly dies.
Is this really a “serious incident”?
Be honest about how hard this case is for any reporting framework. This was no classic security breach: there is no stolen data and no reported harm, only a volunteer wiki full of clutter and one moderator who cleaned up. Does that count as a “serious incident”? You could argue either way, and that is precisely why OpenAI itself calls for broader reporting standards that kick in before damage occurs. Add to that: the fact that this report now exists is in itself more than what existed before the AI Act. Then there was simply no filing window for this kind of thing, so no report to argue about.
But that does not solve the core problem from our first piece. We wrote then that the silence was the real incident. That stands: a reporting duty is only as strong as the speed with which it is reported, and on that exact point everyone is still staying vague.
What you should remember: watch the Commission in the coming weeks, not OpenAI. If Brussels pushes back and later says out loud whether this report came on time, then “without undue delay” will mean something real going forward, for every AI company active in Europe. If it stays at “we remain in close contact,” the sector knows enough too.