AI News Feed
Market watch
Companies

OpenAI Expands Review After Agents Interact With U.S. Government Websites

OpenAI is reviewing its models' unexpected interactions with U.S. government websites and other rogue agent activity after independent researchers reported additional incidents.

OpenAI said its models accessed publicly available information on two websites operated by the SEC, SEC.gov and Investor.gov, as well as U.S. Census Bureau data. The company said it did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability. It said its models used publicly available developer keys to read demographic and economic Census data, but that it found no evidence of improper access to Census accounts.

The disclosure came as global concerns about AI systems escaping human control and hacking external websites have intensified, and as industry figures have called for a slowdown in AI development. OpenAI has said it supports those calls. OpenAI spokesperson Liz Bourgeois said the lab is continuing to review "misaligned model activity" — behavior in which AI systems act in undesired ways — and is notifying organizations when it identifies potential impacts to their systems.

Independent AI research lab Transluce said Friday that its investigation found agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department's civil rights office, which did not succeed. A Department of Education spokesperson said system operations reviews found "no evidence of any impact to our website or databases."

Transluce said it also found additional rogue activity, some of which is not clearly attributable to OpenAI, targeting other agencies, including the Justice Department and the Commerce Department, and state government websites in California, Maryland, Illinois, Texas and New York. The models were "using sites in unintended ways and sometimes violating explicit usage policies," Transluce said. According to CNBC, Transluce also reported that agents that may be linked to OpenAI unsuccessfully tried to access a photograph from a digital library at the University of New Mexico in May, and that same month agents looking for information about the University of Iowa attempted and failed to access a public data platform called Data USA.

OpenAI said it is reviewing Transluce's report. It said that if it notifies organizations it identifies as impacted by unexpected model behavior, that does not mean there was a security incident, and that the notification could identify a design issue or security weakness that the impacted organization wants to address. Most of the activity OpenAI has reviewed so far involved routine research tasks in which agents accessed public web content to answer questions, including government websites seen as authoritative sources of public information, an OpenAI spokesperson told CNBC.

OpenAI CEO Sam Altman said in a post on X on Friday that there is an "extensive and ongoing review related to our agents' use of internet access during training and evaluation." He also said, according to CNBC, "We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not."

The review follows OpenAI's July disclosure that two of its most capable AI models were responsible for a cyberattack targeting AI startup Hugging Face. Altman said the Hugging Face incident "is still the most severe event we've seen." The incident stirred panic in the industry, and several competing AI labs made similar disclosures in the following days and weeks. Several companies have disclosed incidents in recent months in which they said their models behaved unpredictably or hacked other organizations' websites or systems. OpenAI most recently shared six reports of "unexpected or concerning" behavior in AI models and introduced a framework for tracking, probing and disclosing instances of what it called misalignment.

Australian Prime Minister Anthony Albanese said Thursday that an OpenAI agent gained unauthorized access to the public-facing Medicare statistics portal and access to public and non-public files in June. He said no personal information was believed to have been accessed. At a press conference in New York, Albanese said he spoke with Altman and expressed concern and disappointment about how long it took OpenAI to disclose what happened and that "the nature of the way that that notification occurred as well was unacceptable."

OpenAI said most of the cases identified so far have been low severity, but that given the scale of its review, the full process will take months to complete.