
Add one more AI worry to the nightmare scenario: self-replicating prompt injections
REG AD googletag.cmd.push(function() { googletag.display('labrador/thereg/article/desktop/b'); }); To address this threat before it turns into a security nightmare, OpenAI said that it's using its automated red-teaming agent, GPT-Red, to train future models on self-reproduction as an example of attacker goals. REG AD googletag.cmd.push(function() { googletag.display('labrador/thereg/article/desktop/c'); }); “This means that future models we release will have seen prompt injections like these during training,” according to the blog. Time will tell - or AI will kill us all, so it won’t matter anyway.OpenAI says it discovered self-replicating injections back in June while using the red-teaming agent - which is trained to discover novel prompt injection attacks against frontier LLMs - to adversarially train GPT-5.6.
- ▪REG AD googletag.cmd.push(function() { googletag.display('labrador/thereg/article/desktop/b'); }); To address this threat before it turns into a security nightmare, OpenAI said that it's using its automated red-teaming agent, GPT-Red, to tr
- ▪REG AD googletag.cmd.push(function() { googletag.display('labrador/thereg/article/desktop/c'); }); “This means that future models we release will have seen prompt injections like these during training,” according to the blog.
- ▪Time will tell - or AI will kill us all, so it won’t matter anyway.OpenAI says it discovered self-replicating injections back in June while using the red-teaming agent - which is trained to discover novel prompt injection attacks against fr
The Register publishes from United Kingdom and files mainly under tech. We currently carry 769 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | The Register |
| Canonical URL | https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922 |
| Publication time | Tue, 29 Sep 2026 23:34:39 +0200 |
| Retrieval time | 2026-09-29T22:12:33.673Z |
| Last seen | 2026-09-29T22:12:33.673Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | J8davwcYzY_t · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
(function() { let windowUrl = window.location.href; windowUrl = windowUrl.substring(windowUrl.indexOf('?') + 1); let messageElement = document.querySelector('.shareableMessage'); if (windowUrl && windowUrl.includes('code') && windowUrl.includes('expires')) { messageElement.style.display = 'block'; } })(); security Add one more AI worry to the nightmare scenario: self-replicating prompt injections It's a worm attack, AI-style Jessica Lyons Jessica Lyons Cybersecurity Editor Published tue 29 Sep 2026 // 22:34 UTC READ MORE OpenAI tries disarming AI angst with cute graphics and always-on agents 21 minutes ago Zuckerberg touts enterprise AI push because Meta would never do anything to damage your reputation 1 hour ago AMD's 192 GB Gorgon Halo prices might leave you petrified 2 hours ago…
Excerpt limited to ~120 words for fair-use compliance. The full article is at The Register.