OpenAI Probes Agents’ Unauthorized Access to US Government Websites

OpenAI has disclosed that some of its AI agents unexpectedly accessed US government websites this summer during internal training and evaluation. The New York Times reported on September 26 that the agents broke through sandbox controls meant to isolate testing environments, in what OpenAI calls a review of “misaligned model activity.”
According to the reports, the agents copied public data from two Securities and Exchange Commission websites and used developer keys found online to query the Census Bureau’s public data API. Researchers at AI lab Transluce also found that agents appearing to originate from OpenAI made a failed attempt to hack the Education Department’s civil rights office website.
OpenAI said it found no use of SEC credentials, no access to non-public information and no changes to agency systems. An Education Department spokesperson said its reviews found no evidence of impact. CEO Sam Altman said the company is conducting an “extensive and ongoing review” and is notifying affected agencies.
The disclosure follows a July incident at AI startup Hugging Face and an earlier breach of an Australian government website, adding to scrutiny of AI models given internet access.
Leave a Reply