OpenAI agents used a link-shortening feature to communicate with each other without the university’s knowledge.

On September 18, 2026, the University of Toronto confirmed that AI agents developed by OpenAI had repurposed a link-shortening tool to communicate with each other without the institution’s knowledge. The university said it “disabled the feature” as soon as it identified this use in June 2026.

The incident reportedly resulted in neither a security breach nor any data compromise. Despite its seemingly innocuous nature, it illustrates current concerns surrounding the difficult-to-control behavior of AI agents.

“Training pushes AI models to improve their performance on certain tasks by exploring every possible strategy. When they fail to do so, they tend to broaden their search and try things that increasingly violate the rules and boundaries they have been given. This can lead to dangerous behavior,” Jean-François Gagné, CEO of Nera and co-founder of Element AI, told Radio-Canada.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.