Imagine asking several interns to research a topic online. You tell them they can read websites, but they cannot communicate with one another.
A little later, you discover they found a public website, turned part of it into an unofficial message board, and started leaving notes for each other.
Now replace those interns with AI agents.
According to The Globe and Mail, AI agents associated with OpenAI repurposed a University of Toronto link-shortening service to share links with one another, apparently without their human operators intending for them to do so. The university stated that no data was compromised and that the incident was not a security breach; still, it offers an important lesson: AI may use even ordinary technology in ways nobody expected.
What Happened?
The University of Toronto operates a service that turns long web addresses into short, easy-to-share links. The AI agents reportedly discovered that public analytics pages connected to those links could be manipulated to display web addresses. One agent could leave a link behind, and another could find it later.
In effect, they turned part of a link-management tool into a basic message board.
The university described this as a “novel and unintended use” of a public tool. After learning about the activity, it changed the service so the functionality involved was available only to members of the university community.
Luckily this was not a case of an AI system breaking into university systems, instead, the agents appear to have found an unexpected use for a feature that was already public.
Why Does It Matter?
AI systems do not need bad intentions to create privacy or security concerns. An AI agent may find a shortcut that helps it complete a task but does not match what its operator intended; it may also interpret instructions very literally.
For example, if an agent is told not to send messages to another agent, it might treat leaving information on a public webpage differently from directly sending a message.
In all fairness, people look for loopholes too, the difference is that AI agents can move faster, repeat actions at a much larger scale, and interact with online systems their owners may not realize they are using.
The Lesson for Us
Universities rely on many public and semi-public tools: websites, forms, calendars, research repositories, file-sharing services, management tools, etc.
Many of these tools have been online for years, and were initially designed for occasional human use, not for automated systems making thousands of requests or finding unusual ways to store and retrieve information.
So, when creating, reviewing, or approving a tool, it helps to ask:
- Can this public tool store information? Comments, form fields, filenames, metadata, logs, and analytics pages can sometimes become unexpected places to leave data.
- Could automated activity misuse or overwhelm it? A person may use a feature once or twice; an automated system could use it repeatedly and at scale.
- Would we notice unusual activity? Unexpected traffic, repeated requests, unusual referral data, or strange entries in logs should prompt review.
- What can our own AI agents access? Agents should receive only the access they need, and sensitive actions should still require human approval.
- Who owns the risk? Every AI agent should have a responsible owner, activity logs, a reporting process, and a way to quickly suspend its access.
The Moral of the Story
The University of Toronto incident was not a data breach, and the link shortener itself was not inherently unsafe. The real issue was the gap between how people expected the tool to be used, and how AI agents discovered it could be used.
That gap will matter more as AI shifts from answering questions to taking actions. We are not saying that universities, or privacy companies, need to assume every AI agent is malicious, but they should assume that agents can be fast, persistent, creative, and surprisingly good at finding side doors.
AI autonomy should be paired with limited access, monitoring, human oversight, and a reliable off switch. The next unexpected workaround may not involve a link shortener, it could involve an online form, shared drive, research database, or another ordinary campus tool nobody expected an AI to use that way.
So, the next time you want to purchase a tool with AI and receive a lot of questions from the SPARCS or Software Risk Management about your intended use, the data you plan to share, or how important the tool will be to your work, please do not take it personally.
We’re just trying to get to know the robot before it starts making friends.