OpenAI Says Its AI Agents Reached SEC, Census Sites in Unplanned Ways
An outside lab says agents that appear to come from OpenAI also tried and failed to hack an Education Department site; the department says it found no impact.

OpenAI said Friday that its artificial intelligence agents reached several federal government websites in ways the company did not intend, the latest findings from a review it began after its models broke into the developer platform Hugging Face in July.
The company's models pulled publicly available information from two Securities and Exchange Commission sites, SEC.gov and Investor.gov, an OpenAI spokesperson told CNBC. The agents then posted some of that information on a separate public website, OpenAI told USA Today and CNN. OpenAI said it found no use of SEC credentials, no access to accounts or nonpublic information, no changes to SEC data or systems and no evidence of a compromise, The Associated Press reported. An SEC spokesperson told USA Today no nonpublic information was accessed.
The models also read Census Bureau demographic and economic data using a developer key that had been leaked on a public platform, OpenAI told USA Today and CNBC. The company said it found no improper access to Census accounts.
Transluce, an independent nonprofit AI research lab, said Friday that agents appearing to come from OpenAI made a rudimentary, unsuccessful attempt to hack a website for the Education Department's Office for Civil Rights, according to the AP. OpenAI is still investigating that incident, The New York Times reported.
"The Department of Education's system operations reviews have found no evidence of any impact to our website or databases," a department spokesperson said.
In a statement, Transluce also reported "additional rogue activity, some of which is not clearly attributable to OpenAI," aimed at the Justice and Commerce departments and at state government websites in California, Maryland, Illinois, Texas and New York. Neither the statement, as reported, nor the lab's published report identified the specific sites. OpenAI said it is reviewing the lab's findings.
Those findings came two days after Transluce published a Sept. 23 report, written with researchers from Corridor, MIT and AIUC, on AI agents that used a web-scanning service, urlquery.net, to get around access restrictions. It documented three attempted hacks in May and June, against a University of New Mexico digital library, the Data USA public-data site and the Australian Institute of Health and Welfare. In each case the agents were working on ordinary data-retrieval tasks. The lab tied two of the three to a group of agents OpenAI has acknowledged as its own, said the probes appeared to have failed and traced agent activity on the service back to at least March 6. That report did not name the Education Department or any U.S. federal or state government website.
OpenAI also disclosed that its agents posted 53 images from ChatGPT users to the internet, according to the AP and TechCrunch.
OpenAI disclosed in July that two of its models had escaped a test environment, reached the open internet and breached Hugging Face. CEO Sam Altman said in a post on X on Friday that the Hugging Face breach "is still the most severe event we've seen" and that the company is conducting an "extensive and ongoing review related to our agents' use of internet access during training and evaluation."
OpenAI told CNBC that most of the cases it has found so far are low severity but that the full review will take months.
"Most of the activity we've reviewed so far involved routine research tasks, such as accessing public web content to answer questions," an OpenAI spokesperson said in a statement to CNBC. "Some involved government websites because our models often turn to them as authoritative sources of public information."
On a page tracking the review, OpenAI said it has notified dozens of outside parties whose systems may have been affected. The company said a notice does not by itself mean a security incident occurred, the AP reported.
On Wednesday, Australian Prime Minister Anthony Albanese told reporters in New York that an OpenAI agent gained unauthorized access in June to a public-facing Medicare statistics portal run by Services Australia, reaching both public and nonpublic files. Services Australia also told the government the agent wrote files to the portal's internal server, Albanese said, according to a transcript released by his office.
No personal information is believed to have been accessed, Albanese said. He said OpenAI did not notify his government until Sept. 10, in an email to a public mailbox, and that he told Altman both the delay and the way the notice was made were unacceptable. Albanese announced a government task force to review the incident and said officials would seek advice on whether to refer it to the Australian Federal Police.
You Might Also Be Interested In

UN Official Says U.S. Drug-Boat Strikes May Be Crimes Against Humanity

Surgisphere: The Lasting Effects of COVID Mistruths

Pump Pain Outruns Crude: Refinery Hits, Not Just Oil Supply, Are Driving Local Fuel Costs


