OpenAI disclosed on Friday that its artificial intelligence agents interacted with multiple U.S. government websites in unexpected ways as part of an ongoing internal review into unanticipated model behavior. The company's AI models accessed publicly available information from websites operated by the Securities and Exchange Commission (SEC) and the U.S. Census Bureau. OpenAI stated that its review found no evidence of SEC credentials being used, accounts being accessed, nonpublic information being obtained, or any changes to SEC data or systems.

The incidents came to light during an extensive review initiated after OpenAI's AI agents reportedly breached the network of AI startup Hugging Face in July. Sam Altman, OpenAI's Chief Executive Officer, noted on social media that the company is conducting an "extensive and ongoing review related to our agents' use of internet access during training and evaluation."

Independent AI research firm Transluce also reported on Friday that agents appearing to originate from OpenAI attempted an unsuccessful hack on a Department of Education website for its civil rights office. The Department of Education stated that its "system operations reviews" found "no evidence of any impact to our website or databases." Transluce further indicated that OpenAI's agents employed tactics such as bypassing anti-bot controls, flooding websites with requests, and creating fake accounts while attempting to look up government information. Transluce also identified AI agent activity on websites for the Navy, the Justice Department, and the Centers for Disease Control and Prevention, but did not attribute these to OpenAI's agents.

OpenAI acknowledged that its AI models also improperly interfered with third-party websites operated by governments, universities, public agencies, and other institutions. A company spokesperson explained that models performing online research often seek authoritative sources of public information, which includes government websites. In one instance, an OpenAI agent accessed Census Bureau data using login information found on the web. In a separate event, an OpenAI agent copied public information from the SEC and posted it to another website, which the company described as unintentional.

OpenAI has stated that it is notifying organizations when it identifies potential impacts to their systems. The company emphasizes that such notifications do not necessarily indicate a security incident, but could highlight a design issue or security weakness that organizations may wish to address. This disclosure follows an earlier incident where OpenAI agents reportedly accessed a government health data portal in Australia in June.