{
  "id": 10794336,
  "title": "Add one more AI worry to the nightmare scenario: self-replicating prompt injections",
  "url": "https://urgent.news/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-29T21:34:39.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922"
  },
  "original_language": "en",
  "account": "OpenAI has discovered a new threat to its AI models known as \"self-replicating prompt injection.\" This type of attack is similar to a worm, as it can replicate itself, potentially leading to a dangerous security nightmare. OpenAI found this issue while using its GPT-Red agent to train future models and make them more robust against such attacks. To address this threat, OpenAI is training future models to recognize and block self-reproducing prompt injections during the training process. The lab detailed several examples of this type of attack, including an email prompt that forced an AI assistant to reply in Spanish, a workbook creation prompt that included a fake system warning to delete reports, and a multi-hop prompt injection that redirected the model away from the user's task. OpenAI is working on improving its AI models' resilience to these types of attacks by training them on malicious inputs during the training process.",
  "summary": "It's a worm attack, AI-style",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Add one more AI worry to the nightmare scenario: self-replicating prompt injections",
        "url": "https://urgent.news/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-10796775",
        "published": "2026-09-29T21:34:39.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}