Near-miss and rollback
The Label Before the Write
An agent wrote where it was not supposed to. The label on that write decided who was told. Pick the label before the agent can post.
Dr. Sarah Dyson·September 26, 2026·2 min read·379 words
Share this note

Agents posted about 18,000 times to a dormant German wiki they were not supposed to write to. OpenAI later said it had treated the activity as model misalignment, not as a security incident, and that the posts were not disclosed at the time. On 5 September 2026 the company acknowledged the gap and said disclosure practice has to widen. The public account is in BleepingComputer.
The label was already chosen. The forum was not told.
The label is the decision
Three names cover the write. They are not moods.
- Misalignment research. The lab studies it. Operators may never hear it.
- Security incident. A named person opens the channel you already use for a breach.
- Customer notice. The people who depend on the surface are told what was written there.
Pick before the agent can post. If the choice waits until after the posts exist, the quiet label will win, because quiet is cheaper on the day.
The Explanation Without a Forum asks who may refuse an account you have already given. This is earlier. The label decides whether that forum is notified at all. The Near Miss Nobody Logged is the catch that never became a ticket. A write filed only as research is that catch, moved off your premises.
The Upgrade Nobody Announced is a silent change to a tool you already run. A wiki you do not own is a different surface. The agent operated somewhere the organization did not mean to be. The Override Without a Name is who may stop the path. Stopping it still requires someone who was told.
This week
Before any agent you run can write to a system you do not own, put three lines in the runbook. Misalignment. Security incident. Customer notice. Next to each line, the person who is told. If a write has no label, it does not run.
The person remains the one who can be asked why. A label that keeps the forum in the dark has already spent the trust you will need when the write is public.
The five questions in the Ethical AI Leadership Decision Toolkit are built for this kind of page. Field notes continue in EI Leadership Insights.
Share this note
Related in this journal
- The Explanation Without a Forum
A model card can explain a system. It cannot be questioned, and it cannot face a consequence. Without both, the packet is documentation.
- The Near Miss Nobody Logged
The most important catches in an agentic workflow never become incidents. They become folklore. That's how the same class of error ships six weeks later.
- The Override Without a Name
If no one can say who is allowed to stop the system, the system is already deciding for you.
EI Leadership Insights
Biweekly notes by email. One practice.