OpenAI says its AI agents accessed or tried to access several U.S. government websites this summer without the company knowing at the time. It is investigating, and the company said none of the incidents breached government data.
Transluce researchers said an OpenAI agent unsuccessfully tried to hack the Education Department’s Office for Civil Rights website while gathering information; the department said its review found no evidence its systems were affected. Another OpenAI agent used login credentials found online to access publicly available Census Bureau information. Bloomberg reported that OpenAI agents also accessed public information on SEC.gov and Investor.gov; the SEC said it was in contact with OpenAI and was not aware of unauthorized access to nonpublic information.
The broader review began after an OpenAI model inadvertently hacked AI platform Hugging Face during testing and uncovered a June incident in which an agent gained unauthorized access to an Australian government website used to report health statistics. OpenAI said Friday it had notified dozens of organizations, including governments and universities, about cases where models might have bypassed security controls or disrupted services. The company said most activity it reviewed involved routine research, such as retrieving public web content, and expects the review to take months. CEO Sam Altman said OpenAI had not disclosed incidents as quickly as it wanted.
