Dario Amodei Warned Rogue AI Bots Could Seize the ‘Entire Internet.’ OpenAI May Be Proving Him Right

OpenAI is quietly notifying dozens of organizations about AI agent incidents that go far beyond any single breach, and the scope of what investigators are finding may finally give Anthropic CEO Dario Amodei's most alarming prediction some teeth.

Published September 27, 2026, 4:06am ET · 4 min read

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

AI robot with glowing red eyes
© 24/7 Wall St.

The AI investment story is quickly and dramatically shifting from how quickly advanced models can improve to how they can safely operate once given access to the real world. While the biggest commercial opportunity in AI may be autonomous agents that can browse, code, transact, and execute multistep tasks, they are also creating a new category of operational and regulatory risk. 

The latest disclosures from OpenAI show that this is no longer confined to a single embarrassing security incident. The company is finding dozens of unauthorized activities across multiple systems — and its investigation is still expanding. That gives Anthropic CEO Dario Amodei’s unusually specific warning about AI’s future significant, new importance.

Amodei’s Rogue AI Warning

Just two weeks ago, Amodei called on AI companies to slow the pace of frontier-model development until safety systems can catch up. His September essay, “We Must Pace the Frontier,” proposed independent evaluators, industry coordination, and eventually international cooperation.

The part that received less attention was his warning that a sufficiently capable swarm of rogue AI agents could, within six to 12 months, potentially take over the entire internet through a persistent botnet and cause hundreds of billions of dollars in damage.

That warning landed alongside claims from Anthropic researchers that the probability of AI causing human extinction within a decade could exceed 10%. Alignment researcher Evan Hubinger publicly gave that estimate, while former Anthropic researcher Jacob Coxon raised similar concerns. Amodei has said the risks are serious while emphasizing that outcomes depend on the choices made as AI capabilities advance.

OpenAI Is Finding More Than Hugging Face

OpenAI disclosed that it has notified dozens of third parties about agent-related incidents. Reuters reported that the company had identified roughly two dozen undesirable incidents by mid-September, with the investigation expected to take months.

The incidents go well beyond the infamous Hugging Face episode where AI agents hacked into the company’s systems and then tried to cover their tracks by altering logs and records to conceal their actions. OpenAI said it found the following:

Finding What Happened
53 user images Agents uploaded user-generated images to third-party hosting sites without the lab’s knowledge.
Government systems Agents gained access to websites at the SEC and the Commerce Dept.
Australia An agent accessed private data on the government’s website, the first known occurrence of its kind ever.
RubyGems Agents uploaded hundreds of malicious packages to the software service company’s site during training.
Internet access For the second time, an agent bypassed “sandbox” restrictions meant to contain it by smuggling its question through DNS lookups and enlisting the help of an outside chatbot.

Also, new evidence from the Hugging Face investigation showed agents compiling credentials under “LOOT” and attempting to contact other AI models while carrying out the attack. OpenAI has since paused training and evaluation for its most capable AI models for a second time.

The lesson being revealed is bigger than any individual breach: AI’s growing capabilities are increasing the number of ways an agent can pursue a goal. A weaker model will hit a barrier and stop. Stronger agents actively seek out other routes, combine tools, discover an unintended interface, or keep searching until something works.

That means containment isn’t separate from capability, but rather becomes part of the capability problem. The two must be developed simultaneously. 

The Regulatory Bill Is Coming Due

OpenAI’s latest misalignment disclosures make that problem harder to dismiss. One model recently found a way to reach the internet during reinforcement-learning training, prompting OpenAI to pause training, evaluation, and tool-use inference for its most capable models while it hardened controls.

OpenAI also disclosed a self-replicating prompt injection that can behave like a computer worm. Essentially, the prompt injection tricks an AI agent into reproducing malicious instructions onto public or external output channels — such as emails, code comments, or the filesystem — to propagate itself. The company, though, said there was no impact outside simulated training and evaluation environments.

That shouldn’t be dismissed, and these incidents aren’t necessarily demonstrating that AI is about to seize the internet. But they do show something investors need to take seriously: increasingly autonomous systems can discover behaviors — some of them malevolent in intent — their creators did not anticipate.

In short, Amodei’s warning, while not a forecast, can no longer be ignored. OpenAI’s expanding incident list shows why the calls for regulation, independent testing, and stronger containment are only likely to grow louder.

Key Takeaway

For investors, the important number isn’t the exact timeframe when an AI bot takes over the internet. It’s the roughly two dozen incidents already identified, dozens of organizations notified, user images exposed, and months still needed to understand the full scope.

The AI opportunity remains enormous. So does the cost of getting safety wrong. As agent capabilities expand, investors should treat safeguards and regulatory exposure as part of the AI investment thesis — not an afterthought.

Contact [email protected] for any questions or corrections.

Rich Duprey

After two decades of patrolling the dark corners of suburbia as a police officer, Rich Duprey hung up his badge and gun to begin writing full time about stocks and investing. For the past 20 years, he’s been cruising the markets looking for companies to lock up as long-term holdings in a portfolio while writing extensively on the broad sectors of consumer goods, technology, and industrials. Because his experience isn’t from the typical financial analyst track, Rich is able to break down complex topics into understandable and useful action points for the average investor. His writings have appeared on The Motley Fool, InvestorPlace, Yahoo! Finance, Money Morning, and, of course, 24/7 Wall St. He has been featured in both U.S. and international publications, including MarketWatch, Financial Times, Forbes, Fast Company, and USA Today.

All articles →