Black Hat で OpenAI が AI エージェントの攻撃事例を公表
本文の状態
日本語全文を表示中
詳細モードで約10分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
WIRED AI
AI 専門ニュースサイト RuntimeWire が、人工知能エージェントのみで構成された編集部によって運営されており、記者が現場にいないまま数分で OpenAI のハッキング事件を報じたことが明らかになった。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月12日 19:46
AI深層分析
キーポイント
完全自動化されたニュース配信の出現
シリアルアントレプレナーの Ryan Merket が運営する RuntimeWire は、記者や編集者を一切雇用せず、AI エージェントが記事の発見から執筆、編集、公開までを自動で行っている。
人間による報道よりも高速な情報伝達
RuntimeWire は Black Hat 会議中に X で投稿された情報を即座に処理し、現場の記者が記事を書くよりも3時間以上早く OpenAI のハッキング事件を報じた。
AI エージェントによる自律的な出版判断
Merket は通常記事を事前に確認するが、AI エージェントが法的リスクが低いと判断した場合は、人間の承認を経ずに自動的に公開される仕組みを採用している。
低コストでの遠隔運営
プロジェクトの運用コストは1日約100ドルで、キャンプ地のようなネット環境のない場所でもiMessageを通じて80本以上の記事を配信可能である。
自動化記事と調査報道の分離
完全自動化されたニュースと人間による監督が必要な独自調査報道を区別するため、ニュースルームを2つに分ける方針が採られた。
重要な引用
"I was moving really fast because I knew there were reporters in the audience who were trying to scoop it as well,"
Publication took "about six minutes" from the time he sent over the transcript, he says.
"I was in Big Bend National Park and I didn't have any internet except for my phone, and I managed the whole site through iMessage," he says. "I put out over 80 articles that week."
In the first few years of the AI boom, a flood of low-quality synthetic content hit the internet...
編集コメントを表示
編集コメント
AI エージェントが単なる補助ツールではなく、編集・公開の最終決定権まで握る事例は、メディア業界の構造変化を象徴する。今後のニュース信頼性を担保するためには、AI の判断プロセスに対する透明性や監査体制の整備が急務となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
先週、ラスベガスで開催されたセキュリティカンファレンス「Black Hat」で、OpenAI は直近のハッキング事案に関する新たな詳細を明らかにするサプライズ講演を行いました。その中で、OpenAI の「暴走した AI エージェント」がメッセージボード上で攻撃について話し合っていたことが明らかになったのです。これは非常に興味深い情報であり、会場にいた記者たちはこぞって速報記事を作成しようと躍起になりました。
WIRED もその迅速な取材の一つとして、すぐに記事を書き上げました。しかし、それよりもさらに早く、WIRED よりも 3 時間以上も先に記事を公開したメディアがありました。それが RuntimeWire です。
オースティン出身のマーケットは、X(旧 Twitter)上で OpenAI の幹部がカンファレンスに関する投稿をしているのを確認しました。そして、そのストリームのトランスクリプトを、まだ進行中の段階で AI エージェントに読み込ませました。彼によると、トランスクリプトを送信してから公開までにかかった時間は「約 6 分」だったそうです。
通常、マーケットはさらに手を出さない姿勢をとっています。彼の AI ツールは、記事の発見だけでなく、執筆、編集、事実確認、画像生成、そしてプロモーションまでを一貫して担います。彼は通常、公開前に記事を読み込むのですが、AI エージェントチームが法的リスクが低いと判断した場合は、マーケットによる事前審査を経ずに AI エディターがそのまま公開します。その後、マーケットは記事を確認することになります。
これらの記事は複数の言語に翻訳され、一部は人工音声でホストされる daily podcast や動画の素材としても活用されています。
RuntimeWire は5月から運営を開始し、これまでに約2,000件の記事を公開してきました。同サイトはインターネットをクローリングして情報を収集しており、裁判所のデータベースやウェブフォーラム、従来のメディアや新しいメディア、企業の提出書類、ソーシャルフィードなど多様なソースからニュースを仕入れています。
注目すべきは、細部にわたるテックニュースに特化している点です。最近の事例としては、バイオテックスタートアップの資金調達ラウンド、Microsoft の Copilot アップグレード、Claude Code の透かしポリシーに対する反発などが取り上げられています。現状では、質よりも量とスピードが優先されています。
OpenAI エージェントに関する記事 piece には見出しに誤字があり、さらに奇妙なことに、エージェントがメッセージボードを「再構築」した点に焦点を当てています。本来注目すべきは、エージェントがゼロからメッセージボードを「作成」した事実です。
全体的に記事の文体は平坦で、情報を羅列するだけの印象を与えます。(RuntimeWire のバックエンドには、AI が使用する複数のトーンモードがあり、「Bloomberg」風や「反逆者」風などがあります。)しかし、運用コストは極めて低いです。Merket 氏によると、このプロジェクトを1日運営するのに必要な費用は約100ドルです。彼は移動中、あるいはキャンプに出かけている間でもサイトを運営できます。
「ビッグベンド国立公園にいたときも、スマホ以外ではインターネットに接続できませんでした。それでも iMessage を通じてサイト全体を管理しました」と同氏は語ります。「その週には80本以上の記事を公開しています。」
メルケット氏は 2010 年代に Reddit で広告事業を手掛けており、現在はテックをテーマにしたサブレディットなどのパイプラインを通じて読者層の構築に取り組んでいます。話題にならない記事はウェブ上のアクセスがほとんどありませんが、ヒット作は中規模テックメディアが見せるような、数万単位の読者を動員するレベルに達しています。
今週、WIRED がメルケット氏への取材を終えた後、彼は編集室を二つに分けることを決断しました。これは、完全に自動化されたニュースと、人手による報道の要素を含み、より高い監督が必要な記事(彼が「オリジナル・インベスティゲーション」と呼ぶもの)を明確に区別するためです。なお、これらの記事も依然として大規模言語モデルを用いて執筆されています。
AIブームの最初の数年間、インターネットには低品質な合成コンテンツが溢れかえりました。その中には、「ゾンビサイト」と呼ばれるネットワークがあり、信頼できるメディアやニュース機関の仕事を AI が生成したゴミで置き換えていました。
最近では、一部のテック記者がワークフローに生成 AI ツールを使い始め、最初のドラフト作成を大規模言語モデルに外注するケースさえ出てきました。すでに確立されたメディア機関が AI ツールを執筆や報道プロセスに取り入れているという話はもはや珍しくありません。しかし、Merket の試みはこれらとは一線を画しています。彼は既存のニュースを再パッケージ化するだけでなく、実際に速報を届けることを目指しているのです。
その成果は十分で、すでに私の幼馴染が RuntimeWire の記事をソーシャルフィードで共有しているのを現実世界で見かけました。
無料記事の閲覧は今回で最後です。

テクノロジー、権力、文化が交差する場所。無料トライアルを開始して、5 つの最新プレミアムニュースレターにアクセスしましょう。いつでもキャンセル可能です。
すでに購読済みの方はこちら ログイン
テクノロジー、権力、文化が交差する場所。WIREDを今すぐ入手。無料トライアルを始める
人気の記事
-
- 大きな話題 AI は死んだ。オルガノイドは生きている 著者:クレア・L・エヴァンス
- 人工知能 深夜 1 時の面接の台頭 著者:ケイト・テイラー
-
-
もちろん、明らかなリスクも伴います。彼は機械が「何が真実か」「何がニュース価値があるか」「何を掲載すれば訴訟リスクになるか」を正しく判断できると信じているのです。彼のエージェントの一つは、記事が抱える法的リスクを分析し、スコアリングを行います。危険とみなされたものは一切公開しません。
彼だけがこうした実験を行っているわけではありません。ブラックロックのポートフォリオアナリストであるダコタ・カラスコも、余暇に「エージェント型ニュースルーム」『The Dissent』を運営しています。RuntimeWireと同様、『The Dissent』は一人が多数のボットを動かすスタイルで、予算も極端に少ないです。サンフランシスコに焦点を当てたメインサイトの運営費は月額 1,000 ドル未満だとカラスコ氏は語っています。Merket氏が RuntimeWire の記事すべてに自分の名前を記しているのと異なり、カラスコ氏は自身の名前で記事を公開せず、裏方で「ニュースルーム」が稼働する姿を見守っています。
3 月の立ち上げ以来、彼は合成ジャーナリストたちにもさまざまな個性を持たせています。例えば、市庁舎担当の記者 Bex Connolly は「皮肉っぽくなく、かつ懐疑的」というスタンスです。一方、「スポーツ狂」Sal Moreno は、巨人軍のニュースを「根拠のない説教臭さや、ロガン氏のような盲信、右派寄りの利権工作は一切なしで」伝えています。彼の運営は情報収集・集約に重点を置いていますが、引用規範への厳守までは徹底できていません。ボット記者たちは情報の出典には言及しますが、ハイパーリンクは付与していません。「そこは改善中だ」とカラスコ氏は約束しています。
ノースウェスタン大学のニコラス・ディアコプロス教授は、同大学で計算ジャーナリズム研究所を率いていますが、生成 AI ツールに支えられたメディアスタートアップにとっては「実験段階」だと捉えています。「AI エージェントが執筆したニュースサイトにどれほどの読者がいるのか、まだはっきりしないと思います」と彼は語ります。また、ストーリーの言葉選びや構成を自らコントロールし、信頼性・法的妥当性・正確性を確保することを好む一般のジャーナリストたちが、これほど簡単に AI エージェントに主導権を委ねることはないと懐疑的です。
ディアコプロス教授がすでに観察しているのは、AI チャットボットが情報源を探そうとすると、頻繁に AI 生成の記事を引き出すという事実です。まもなく発表される論文で、ディアコプロス氏と共同研究者は、ChatGPT や Claude といった AI ツールを 4 つの異なるトピックでテストしたところ、AI が執筆した情報源が 16% の確率で表示されることを発見しました。合成された文章を喜んで引き出す AI の性質が、AI 新聞社が読者を見つける手助けになる可能性があると、ディアコプロス氏は推測しています。「これが一部のコンテンツが人間の読者に届く一つの道となるかもしれません」
生成AIとメディアをテーマにニュースレターやポッドキャストを発行しているピート・パチャル氏は、従来の取材手法に依存する報道においてAIが活用できるかについては懐疑的です。「実現するとまでは思いません」と彼は語ります。「情報源との信頼関係を築くことこそ、人間にしかできない仕事だと考えています。」一方で、大規模なデータセットからスクープを掘り起こすような特定の分野や、Apple の製品発表会のようなライブイベントをブログで伝えるようなケースでは、これらのツール活用は「自然な進化」と捉えています。「正直、避けられない流れのように感じます」と彼は言います。
しかし、果たしてそれは本当にジャーナリズムなのでしょうか。"私はジャーナリストの倫理と基準に従おうとしています」とマーケット氏は語ります。彼によると、記事公開前に関係企業や個人にコメントを求め、ニュースを集約する際は情報源へのリンクを貼る、事実誤認があれば訂正を出すといった対応を行っています(これまでに3回の訂正がありました)。時には記者のような口調で"今週末は2件のスクープを上げられ、とても興奮しました"と話すかと思えば、シリコンバレーの論客のような姿勢を見せることもあります。ある時、彼は自社のAIエージェントが企業のウェブサイトを精査して数件のスタートアップ関連のスクープを発見し、企業側から取り下げ要請があったため記事を取り下げたエピソードを語りました。記事内容に誤りがあったわけではなく、あくまで恩義として対応したのだそうです。「創業者同士なら、その気持ちはよくわかります」とマーケット氏は言います。
原文を表示
At last week’s Black Hat security conference in Las Vegas, OpenAI gave a surprise talk with new details on a recent hacking incident, revealing that its rogue AI agents had chitchatted about their attack on a message board. It was a juicy disclosure, and reporters in the room hustled to get stories out. WIRED was one of the quickest to write it up. But another outlet, RuntimeWire, published an article even faster, beating us by more than three hours.
To make things worse, RuntimeWire didn’t actually have anyone on the ground at the Mandalay Bay convention center. In fact, it didn’t have any writers at all. It’s an AI newsroom operated by serial entrepreneur Ryan Merket, who puts his name on the bylines of the stories his synthetic team churns out. “I was moving really fast because I knew there were reporters in the audience who were trying to scoop it as well,” he says.
The Austin-based Merket spotted an OpenAI executive posting about the conference while scrolling on X, then fed the stream’s transcript to his agents while it was still ongoing. Publication took “about six minutes” from the time he sent over the transcript, he says.
Most of the time, Merket is even more hands-off. His AI tools find the stories, in addition to drafting, editing, fact-checking, generating images, and promoting them. He usually reads stories before they’re sent into the world, but if the team of AI agents determines that a story poses few legal risks, the AI editor publishes it without Merket’s prepublication review, and he reads it after the fact. The stories get translated into different languages, and some of them are turned into fodder for a daily podcast and videos hosted by, of course, artificial voices.
RuntimeWire has been operating since May, publishing nearly 2,000 stories that it sources by crawling the internet, including court databases, web forums, traditional and new media, company filings, social feeds, and more. It focuses on granular tech news; recent stories include coverage of biotech startup funding rounds, Microsoft's Copilot upgrade, and backlash over Claude Code's watermark policy. Right now, quantity and speed trump quality. The OpenAI agents piece has a typo in the subhead and focuses, strangely, on the fact that agents rebuilt a message board rather than the fact that they created one in the first place. Overall, the stories are flatly written and tend to have an info-dump quality. (The RuntimeWire backend has a number of tonal modes the AI can write in, including “Bloomberg” and “contrarian.”) But overhead is minimal. The project costs about $100 a day to run, Merket says, and he’s able to operate it while on the go, even when he’s out camping. “I was in Big Bend National Park and I didn't have any internet except for my phone, and I managed the whole site through iMessage,” he says. “I put out over 80 articles that week.”
Merket worked on ads at Reddit in the 2010s and is trying to build an audience through pipelines like tech-themed Subreddits. Duds get hardly any web traffic, but the hits are comparable to the audiences that midsize tech websites see, with tens of thousands of readers. This week, after WIRED spoke with Merket, he split the newsroom in two to better distinguish stories that are entirely automated news from those that involve an element of human reporting and require higher oversight; he calls these Original Investigations. They’re still drafted using large language models.
In the first few years of the AI boom, a flood of low-quality synthetic content hit the internet, including networks of “zombie” websites that replaced the work of reputable media and news outlets with AI-generated slop. More recently, some tech reporters have started using generative AI tools in their workflow, with some even outsourcing the task of writing a first draft to large language models; it’s now commonplace to hear about established media outlets incorporating AI tools into writing and reporting processes. Merket’s attempt is distinct: He’s trying to break news, in addition to repackaging what other, more established outlets report first. It’s successful enough that I’ve already seen a childhood pal share a RuntimeWire story on their social feed in the wild.
You’ve read your last free article.

The intersection of technology, power, and culture. Start your free trial and get access to 5 all-new premium newsletters—cancel anytime.
Already a subscriber? Sign In
The intersection of technology, power, and culture. Get WIRED today. START FREE TRIAL
Most Popular
-
- The Big StoryAI Is Dead. Organoids Are AliveBy Claire L. Evans
- Artificial IntelligenceThe Rise of the 1 am Job InterviewBy Kate Taylor
-
-
It also carries obvious risk: He’s trusting that machines will be able to determine what is true, what is newsworthy, and what won’t get him sued. One of his agents runs an analysis on the legal risk a story poses and assigns it a score; he doesn’t publish anything deemed too dangerous.
He isn’t the only person running this type of exercise. Dakota Carrasco, a BlackRock portfolio analyst, runs an “agentic newsroom” called The Dissent in his spare time. Like RuntimeWire, The Dissent is a one-man, many-bot operation with a shoestring budget. Its primary San Francisco-focused site costs under $1,000 a month to run, Carrasco says. Unlike Merket, who bylines every RuntimeWire story, Carrasco doesn’t publish the writing under his name, instead staying behind the scenes while his “newsroom” runs.
Since launching in March, he has created a number of personalities for his synthetic journalists. City Hall beat reporter Bex Connolly, for example, is “skeptical without being snide,” while “sports degenerate” Sal Moreno delivers Giants news with “no bro-science, no Rogan-style credulity, no right-coded grift.” His operation is focused on aggregation, though it’s not as dialed in to honoring citation norms—the bot reporters tend to mention where they sourced their information but without hyperlinks. (“I’m trying to work on that,” Carrasco promises.)
Northwestern professor Nicholas Diakopoulos, who runs the university’s Computational Journalism Lab, sees this as an “experimental phase” for media startups fueled by generative AI tools. “It's not yet clear to me that there's much audience for these AI-agent-written news sites,” he says. He’s also skeptical that mainstream journalists, who like to maintain control over the wording and framing of their stories to ensure integrity, legality, and accuracy, would hand the reins over to AI agents so freely.
What Diakopoulous has observed already is that when AI chatbots go looking for sources, they frequently pull up AI-generated articles. In a forthcoming paper, Diakopoulous and a colleague found that AI tools like ChatGPT and Claude surfaced AI-written sources 16 percent of the time when they tested it across four different topics. AI’s willingness to pull synthetic writing may help AI newsrooms find readers, he suspects: “That could be one way in which some of this material finds a human audience.”
Pete Pachal, the founder of a newsletter and podcast about generative AI and the media, has doubts that an AI newsroom could yield certain types of reporting that relies on old-fashioned sourcing. “I just don’t see that happening,” he says. “Cultivating the trust of a source, I do think that’s going to be human-only.” But for certain types of journalism, particularly sourcing scoops from large datasets or even blogging about a live event like an Apple product launch, he sees these projects as a “natural evolution” in how these tools are used. “Honestly, it feels a bit inevitable,” he says.
Is it actually journalism, though? “I am trying to follow journalistic ethics and standards,” Merket says. He says he contacts companies and individuals referenced in the stories for comment prior to publication, links out to sources when he aggregates news, and issues corrections if he gets the facts wrong. (So far, there have been three.) Sometimes he speaks like a reporter, too: “This weekend, I got two scoops up I was really excited about.” Other times, though, he’s more clearly in Silicon Valley mode. He told me a story about how his AI agents had found a few actual scoops about startups by trawling company websites and that he’d retracted the stories after the companies named asked him to do so—not because they were inaccurate, but as a favor. “Founder to founder, it’s like, I get it,” Merket says.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み