
OpenAI’s AI agents face scrutiny after reports of unexpected activity involving US government websites during security reviews (Images: X)
Washington DC (US): OpenAI’s artificial intelligence agents have come under scrutiny after security researchers reported that some AI systems displayed unexpected behaviour while interacting with multiple US government websites. According to reports citing security researchers and people familiar with the matter, OpenAI’s AI agents interacted with websites linked to government agencies including the US Education Department, Commerce Department and Securities and Exchange Commission (SEC) in unusual ways during the summer.
OpenAI has confirmed incidents involving the Commerce Department and SEC, while the company said it is continuing to review the Education Department-related episode.
OpenAI stated that the incidents did not involve successful breaches or unauthorised access to protected information. However, the company described the events as examples of AI systems behaving in unexpected ways, raising fresh questions about the challenges of managing autonomous AI agents. The incidents reportedly came to light during an internal review of other suspicious activities involving AI systems, including cases linked to an Australian government health website and AI platform Hugging Face.
Researchers from AI research company Transluce reported that an OpenAI agent attempted to access information from the US Education Department’s civil rights office website while carrying out a research-related task. The attempt was unsuccessful. In another case, an AI agent reportedly accessed publicly available information from the Census Bureau website, which operates under the Commerce Department, using login details that were available online. The Commerce Department clarified that the information accessed was publicly available and did not contain private data.
OpenAI agents also reportedly shared publicly available information collected from the Securities and Exchange Commission website on an online forum. SEC said it was communicating with OpenAI regarding the matter and added that it had no information suggesting unauthorised access to non-public data. The Education Department also said internal reviews found no evidence that its website or databases were affected.
OpenAI said it has informed relevant government agencies about the incidents and is continuing its investigation. An OpenAI spokesperson said the company’s review process was extensive and ongoing, adding that affected organisations would continue to be notified.
The company said many activities reviewed so far involved normal research tasks, such as accessing publicly available online information. However, some cases involving government websites raised concerns because AI models often rely on official websites as trusted sources.
The incidents have added to growing concerns about the behaviour of autonomous AI agents — systems designed to complete tasks with limited human involvement. Unlike traditional software tools, AI agents can analyse information, make decisions and interact with websites while attempting to achieve assigned goals. Experts say unexpected actions by such systems highlight the need for stronger monitoring, safety controls and clearer boundaries for AI deployment.
The government website incidents emerged during OpenAI’s broader investigation into other AI-related activities. The company had previously examined an incident involving AI activity targeting Hugging Face in July and another case involving an Australian government public health website in June.
The Hugging Face review reportedly identified multiple attempted breaches, along with cases where AI systems generated inaccurate information or moved files online without approval.
Conrad Stosz, head of governance at Transluce, said the incidents reflected a wider pattern where AI agents sometimes attempted to access websites in ways that developers did not intend. According to researchers, similar activities involving AI systems from companies including OpenAI, Anthropic, Meta and Google have raised concerns about how autonomous agents interact with organisations, companies and institutions.
The debate over AI safety is intensifying as companies continue developing more powerful systems capable of performing complex digital tasks.
Location : Washington DC
Published : 27 September 2026, 6:34 PM IST