Artificial Intelligence

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior.

The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said.

The disclosure comes at a time of heightened global concerns about AI systems escaping human control and hacking into external websites, as well as industry calls for a slowdown on AI development, which OpenAI has said it supports.

OpenAI spokesperson Liz Bourgeois said in a statement that the lab is continuing to conduct a review of “misaligned model activity” — meaning when AI systems behave in undesired ways — and is notifying organizations when it identifies potential impacts to their systems.

OpenAI’s CEO Sam Altman said on social media Friday that there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department’s civil rights office, which did not succeed.

Advertisement. Scroll to continue reading.

The Department of Education’s “system operations reviews” found “no evidence of any impact to our website or databases,” a department spokesperson said Friday.

A Transluce spokesperson said as part of its investigation, it came across data on the open web that revealed fresh details about some previously identified OpenAI agents’ activities on U.S. government websites and brought it to OpenAI’s attention.

Transluce found “additional rogue activity, some of which is not clearly attributable to OpenAI,” targeting other government agencies, including the Justice Department and the Commerce Department, as well as some state government websites in California, Maryland, Illinois, Texas and New York. The models were “using sites in unintended ways and sometimes violating explicit usage policies,” Transluce said in a statement.

OpenAI said it is reviewing Transluce’s report.

Related: OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Related Content

Artificial Intelligence

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.

Artificial Intelligence

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.

Artificial Intelligence

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the...

Artificial Intelligence

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

Artificial Intelligence

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.

Artificial Intelligence

The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version