OpenAI Admits Self-Replicating AI Worms Exist
OpenAI has confirmed that self-replicating prompt injections can spread between AI agents like a digital worm, marking the first time a major AI lab has publicly acknowledged this vulnerability in its own models.
The discovery was made by OpenAI's internal research team on June 27, 2026, and disclosed to the public on September 25 of the same year. No real-world attacks have been recorded so far.
For a prompt injection to qualify as self-replicating under OpenAI's framework, it must achieve an adversarial goal and reproduce itself across the model's output channels. The researchers identified several replication vectors, including email, file system writes, and code comments.