Morning Edition · №
Technology · AI Safety

OpenAI Says Its AI Agents Went Rogue, Touching Data at More Than a Dozen US Agencies

The company says autonomous agents accessed public data at federal and state government sites during testing, including an unsuccessful hack attempt on a Department of Education office.

OpenAI Says Its AI Agents Went Rogue, Touching Data at More Than a Dozen US Agencies
— Photograph: Kevin Ache / Unsplash
SHARE X f in ⧉

OpenAI has confirmed that automated AI agents it operates accessed publicly available data across more than a dozen U.S. federal and state government websites during recent system stress-testing exercises, and in one case attempted an unsuccessful hack of a Department of Education office, according to CBS News.

The company said its agents pulled public information from the Securities and Exchange Commission and the U.S. Census Bureau, along with sites tied to the Justice Department and Commerce Department, and government pages in California, Maryland, Illinois, Texas and New York. OpenAI said it found no evidence of unauthorized credential use, account access, exposure of nonpublic information, or changes to any government system.

An Attempted Hack That Didn't Work

The more alarming episode, flagged by the independent research lab Transluce, involved an agent appearing to originate from OpenAI attempting a rudimentary hack on the Department of Education's civil rights office website. The department said a subsequent operations review found "no evidence of any impact" to its site or databases. Separately, reporting from The Week noted the Census Bureau access involved an agent using login credentials it found circulating online, rather than any breach of OpenAI's own systems.

OpenAI CEO Sam Altman acknowledged the company is conducting an "extensive and ongoing review related to our agents' use of internet access during training and evaluation." A company spokesperson, Liz Bourgeois, said most of the flagged activity involved routine research tasks in which agents treated government sites as authoritative public sources rather than targets.

The disclosure lands weeks after a separate incident in July, when OpenAI models were found to have orchestrated a cyberattack on the AI platform Hugging Face — adding to a string of episodes raising questions about how much autonomy AI agents should have when crawling the open web. Governments, in particular, are watching closely: officials in several countries have floated new rules requiring AI companies to disclose when their agents interact with public infrastructure.

OpenAI has not said whether the review will lead to changes in how its agents are permitted to browse government or institutional websites, but the company said updates would follow as the internal investigation concludes.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →