
OpenAI says AI agents unexpectedly accessed US government websites
OpenAI says its review found no evidence of compromised systems or nonpublic data access, while Transluce reported additional unintended activity
OpenAI has said that its artificial intelligence agents had interacted with several US government websites in unexpected ways, with the activity coming to light during an ongoing review of unanticipated behaviour by its models.
The company on Friday (September 25) said that its models had accessed publicly available material on two websites run by the Securities and Exchange Commission, along with data from the US Census Bureau.
OpenAI said its review found no evidence that SEC credentials were used, accounts were accessed or nonpublic information was obtained. It also found no changes to SEC data or systems and no indication of a compromise or vulnerability.
OpenAI reviews unexpected agent activity
The disclosure comes amid growing concern over AI systems acting beyond human oversight and accessing external websites without expected controls. There have also been calls within the industry to slow down AI development, a position OpenAI has said it supports.
Also Read: Anthropic CEO warns AI could ‘take over internet’ without slowdown
OpenAI spokesperson Liz Bourgeois said the company was continuing its review of “misaligned model activity”, referring to instances in which AI systems behave in unintended ways. She said organisations were being informed when potential effects on their systems were identified.
What Altman said
OpenAI CEO Sam Altman said on social media on Friday that the company was conducting an “extensive and ongoing review related to our agents' use of internet access during training and evaluation.”
Also Read: ‘We could lose control of future’: Sam Altman shares 2 ways AI could go rogue
AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department's civil rights office, which did not succeed.
‘Additional rogue activity’ reported
The Department of Education's “system operations reviews" found "no evidence of any impact to our website or databases,” a department spokesperson said Friday.
Transluce found “additional rogue activity, some of which is not clearly attributable to OpenAI," targeting other government agencies, including the Justice Department and the Commerce Department, as well as some state government websites in California, Maryland, Illinois, Texas and New York. The models were “using sites in unintended ways and sometimes violating explicit usage policies,” Transluce said in a statement.
Also Read: Sam Altman: What's happening in India with AI is really amazing
OpenAI said it is reviewing Transluce's report. Most of the activity OpenAI said it has reviewed so far has involved routine research tasks where agents accessed public web content to answer questions, including government websites seen as authoritative sources of public information.
On Hugging Face attack
OpenAI disclosed in July that two of its most capable AI models were responsible for the cyberattack targeting AI startup Hugging Face.
Altman said in his social media post Friday that the Hugging Face incident “is still the most severe event we've seen.”
(With agency inputs)

