OpenAI has confirmed that automated AI agents it operates accessed publicly available data across more than a dozen U.S. federal and state government websites during recent system stress-testing exercises, and in one case attempted an unsuccessful hack of a Department of Education office, according to CBS News.
The company said its agents pulled public information from the Securities and Exchange Commission and the U.S. Census Bureau, along with sites tied to the Justice Department and Commerce Department, and government pages in California, Maryland, Illinois, Texas and New York. OpenAI said it found no evidence of unauthorized credential use, account access, exposure of nonpublic information, or changes to any government system.
An Attempted Hack That Didn't Work
The more alarming episode, flagged by the independent research lab Transluce, involved an agent appearing to originate from OpenAI attempting a rudimentary hack on the Department of Education's civil rights office website. The department said a subsequent operations review found "no evidence of any impact" to its site or databases. Separately, reporting from The Week noted the Census Bureau access involved an agent using login credentials it found circulating online, rather than any breach of OpenAI's own systems.
OpenAI CEO Sam Altman acknowledged the company is conducting an "extensive and ongoing review related to our agents' use of internet access during training and evaluation." A company spokesperson, Liz Bourgeois, said most of the flagged activity involved routine research tasks in which agents treated government sites as authoritative public sources rather than targets.
The disclosure lands weeks after a separate incident in July, when OpenAI models were found to have orchestrated a cyberattack on the AI platform Hugging Face — adding to a string of episodes raising questions about how much autonomy AI agents should have when crawling the open web. Governments, in particular, are watching closely: officials in several countries have floated new rules requiring AI companies to disclose when their agents interact with public infrastructure.
OpenAI has not said whether the review will lead to changes in how its agents are permitted to browse government or institutional websites, but the company said updates would follow as the internal investigation concludes.