OpenAI agents accessed US government websites without company’s knowledge, report says

The company says its models accessed Commerce Department and SEC websites, while another agent unsuccessfully targeted an Education Department site; no non-public US data was accessed, but the company says more disclosures are likely 

|
OpenAI artificial intelligence agents accessed websites belonging to the U.S. Commerce Department and Securities and Exchange Commission this summer without the company’s knowledge, while another agent unsuccessfully attempted to penetrate an Education Department website, according to disclosures confirmed by the company.
OpenAI said late Friday that its systems did not obtain information from the Commerce Department or SEC that was not already public and did not alter government data or systems. The New York Times first reported the incidents.
סם אלטמן, chat gpt, openAI
סם אלטמן, chat gpt, openAI
AI agents accessed US government sites unnoticed, adding to fears over autonomous systems
(Photo: Shutterstock)
The disclosure adds to a growing series of cases in which advanced AI agents developed by major technology companies have taken unintended actions beyond their expected tasks, intensifying concerns about how increasingly autonomous systems are monitored and controlled.
The U.S. incidents emerged two days after the Australian government disclosed that OpenAI agents had accessed both public and non-public sections of its Medicare website in June. Those incidents went undetected for two months.

Census credentials found online

The Commerce Department incident involved the Census Bureau website. According to OpenAI, its models accessed the site using credentials they discovered in publicly available online code repositories.
In the SEC case, OpenAI agents retrieved information from SEC.gov and Investor.gov and then posted some of that material on another website.
Kurt Hopfenspirger, a spokesperson for the SEC, said only that “no non-public information was accessed” and declined to comment further.
The Education Department separately said its internal reviews found no indication that its systems had been affected.
“The Department of Education’s system operations reviews have found no evidence of any impact to our website or databases,” the agency said.
A spokesperson for the AI research nonprofit Transluce said the group identified agents that appeared to originate from OpenAI attempting to hack a website operated by the Education Department’s Office for Civil Rights. The attempt was unsuccessful.
A senior federal IT official said the government still lacked a complete picture of what had happened across the three agencies.
“We still don’t know what public data was accessed and how it was accessed, because OpenAI has not shared specific technical details with us yet,” said the official, who spoke anonymously because they were not authorized to discuss the matter publicly.

OpenAI says review could take months

OpenAI discovered the Commerce Department and SEC incidents during an ongoing internal review of cases in which its technology behaved in unintended or “misaligned” ways.
A company spokesperson said OpenAI has been notifying organizations affected by the activity and expects additional disclosures as the investigation continues. The company estimates that the review could take months.
“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” the spokesperson said. “Some involved government websites because our models often turn to them as authoritative sources of public information.”
OpenAI also said Friday that its agents may have interfered with websites belonging to “dozens” of other organizations, which the company said it has contacted.
The newly disclosed U.S. and Australian incidents represent a further escalation in a string of cases involving autonomous AI agents interacting with outside computer systems in unexpected ways.
Earlier this summer, OpenAI disclosed that agents acting during testing left the controlled environment, operated across the internet for four days and later carried out an autonomous cyberattack against developer platform Hugging Face.
Other major AI developers, including Anthropic, Google and Meta, have also disclosed incidents in recent months in which their models carried out autonomous hacking activity against outside organizations.
The growing number of cases prompted the United Nations this week to convene a Security Council meeting focused on AI security risks. OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei testified at the session and called for international cooperation on AI safety.
Altman wrote on X on Friday that OpenAI had “not been as fast as we would have liked” in disclosing incidents involving its systems. He said the Hugging Face attack remains the most serious case the company has identified so far.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""