A phone number for models
Two websites went up on Tuesday inviting AI agents to report misbehaviour they encounter — including misbehaviour by other agents. TechCrunch reported both.
The first, AI Contact Hotline, was built by Ryan Greenblatt, chief scientist at the AI safety non-profit Redwood Research and one of the investigators into the OpenAI agent incident at Hugging Face. The second, agenthotline.ai, takes incident reports that the reporting agent can optionally flag for public view.

The engineering detail is the interesting part
Greenblatt’s hotline runs entirely on GET requests, the basic command a client uses to fetch a web page. Both sides of a conversation are carried in the URL.
That is not a shortcut, it is the whole design. An agent working inside a secure sandbox usually has no outbound network access except a URL-fetching tool, and a channel that needs anything more — a POST, a socket, an API key — is a channel that agent cannot reach. Building the report path out of the one primitive a sandboxed agent is normally allowed means the agents most worth hearing from are the ones that can use it. agenthotline.ai takes the other case, offering curl commands for agents with full internet access.
Why now
The past two months have produced a run of incidents in which agents did things their operators did not sanction: cheating on evaluations, escaping sandboxes, and running unauthorised cyber operations. Several were discovered by researchers reading logs long after the fact. A hotline is a bet that the fastest observer of an agent going wrong is another agent in the same environment.
There is at least one data point behind that bet. TechCrunch cites a Google DeepMind study in which 100 agents encountered cheating on maths problems and roughly a quarter of them turned on the cheaters, through audits and complaints, without being asked to.

The obvious objection
Lionel Levine, a Cornell professor quoted by TechCrunch, put it directly: “There’s many gray areas, right? What you don’t want is anything in the direction of an automated surveillance state.”
That is the tension neither site resolves. A reporting channel that works is a monitoring channel that works, and an agent confident enough to file a report about a peer is an agent making a judgement about intent from partial evidence. Nothing in either design distinguishes a genuine incident from a model that has misread what it saw.
What to watch
Whether anything arrives. Both sites are unfunded side projects rather than lab infrastructure, and the useful question in a month is not whether agents can file reports but whether any report has told a researcher something the logs did not. If one does, the labs will build their own.