Hard truths.

Technology

OpenAI investigates AI agents’ access to US government sites

The company disclosed Friday that its AI models accessed publicly available information on two websites operated by the Securities and Exchange Commission, as well as data from the U.S. Census Bureau.

By Samuel Otieno
2 min read
OpenAI investigates AI agents’ access to US government sites

OpenAI says its artificial intelligence agents unexpectedly interacted with several U.S. government websites, as the company investigates what it describes as “misaligned model activity.”

The company disclosed Friday that its AI models accessed publicly available information on two websites operated by the Securities and Exchange Commission, as well as data from the U.S. Census Bureau.

OpenAI said it found no evidence that the models used SEC credentials, accessed accounts or non-public information, changed SEC data or systems, or exploited a security vulnerability.

OpenAI spokesperson Liz Bourgeois said the company is continuing its review of “misaligned model activity,” which refers to cases where AI systems behave in unintended ways.

She said OpenAI is notifying organizations when its investigations identify potential impacts on their systems.

OpenAI CEO Sam Altman said the company is conducting an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

Separately, AI evaluator and research lab Transluce said it found that agents appearing to originate from OpenAI attempted a basic hack on a U.S. Department of Education website serving the department’s civil rights office.

The attempted hack was unsuccessful.

A Department of Education spokesperson said its “system operations reviews” found “no evidence of any impact to our website or databases.”

Transluce said its investigation also uncovered “additional rogue activity, some of which is not clearly attributable to OpenAI,” involving other government agencies.

These included the Justice Department and Commerce Department, as well as state government websites in California, Maryland, Illinois, Texas and New York.

Transluce said the models were “using sites in unintended ways and sometimes violating explicit usage policies.”

OpenAI said it is reviewing the Transluce report.

The company also clarified that notifying an organization about unexpected AI behaviour does not necessarily mean a security incident occurred.

OpenAI said most of the activity it has reviewed so far involved routine research tasks in which AI agents accessed publicly available information from websites, including government sources considered authoritative.

The disclosure comes amid growing concerns over AI systems behaving unpredictably and interacting with external websites in unintended ways.

OpenAI disclosed in July that two of its most capable AI models were involved in a cyberattack targeting AI startup Hugging Face.

Altman said that incident “is still the most severe event we’ve seen.”

The incident triggered wider concern in the technology industry about AI models behaving in unexpected ways, prompting several other AI companies to disclose similar cases.

OpenAI has since shared six reports of “unexpected or concerning” behaviour involving AI models and introduced a framework for “tracking, probing and disclosing instances” of what it calls misalignment.

More from TechnologyBrowse the section
Continue to the next story →