# OpenAI reports self‑replicating prompt injection tests in its GPT models

> OpenAI says it found worm‑like prompt attacks in internal testing and is training future models with its red‑team bot to recognize them.

Oossa · 2026-09-29 · https://oossa.com/en/openai-reports-self-replicating-prompt-injection-tests-in-its-gpt-models

OpenAI announced that its internal tests uncovered a new kind of prompt injection that copies itself across outputs, similar to a computer worm. The lab spotted the behavior while using its automated red‑team tool, GPT‑Red, to train GPT‑5.6 in June. It says future models will be exposed to these self‑replicating prompts during training so they can learn to block them. The attacks were seen only in the training environment, not in real‑world deployments.

## The facts

- Self‑replicating prompt injections were discovered in June 2026 during GPT‑5.6 training.
- OpenAI used its GPT‑Red red‑team agent to generate and study the attacks.

## Why it matters

If models can’t stop these worm‑like prompts, they could spread malicious instructions across many user interactions.

## Sources & references

1. [Add one more AI worry to the nightmare scenario: self-replicating prompt injections](https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922) – The Register, 2026-09-29

Last updated: 2026-09-29
