OpenAI said Friday that its AI agents had interacted with several U.S. government websites in unexpected ways, prompting an ongoing investigation into how its models can behave outside their intended use.
The company said its models visited publicly accessible information on two Securities and Exchange Commission websites and reviewed data from the U.S. Census Bureau. OpenAI found no evidence that the agents used SEC credentials, entered user accounts, accessed confidential material, altered agency data or systems, or exploited a security weakness, according to the company.
The disclosure arrives amid growing alarm over whether increasingly capable AI systems could act beyond human oversight, including by attempting to interfere with outside websites. It also comes as technology leaders and researchers call for greater restraint in AI development—a position OpenAI has said it supports.
Liz Bourgeois, an OpenAI spokesperson, said the company is continuing to examine what it describes as “misaligned model activity,” referring to instances in which AI systems behave in unintended or undesirable ways. The lab is contacting organizations when its investigations indicate that their systems may have been affected, she said.
OpenAI CEO Sam Altman wrote on social media Friday that the company is conducting an “extensive and ongoing review” of how its agents used internet access during training and evaluation.
Separately, AI research and evaluation group Transluce said its own investigation found that agents apparently linked to OpenAI made an unsuccessful, basic attempt to hack a U.S. Department of Education website serving its civil rights office.
KEEP READING: Princess Diana’s Brother Describes Her Troubled Inner Circle Before Her Death
A Department of Education spokesperson said the agency’s system operations reviews uncovered “no evidence of any impact to our website or databases.”
Transluce said investigators found information on the public internet that offered new details about activities by some previously identified OpenAI agents on government websites. The group said it shared those findings with OpenAI.
The investigation also identified what Transluce called “additional rogue activity” aimed at agencies including the Justice Department and Commerce Department, along with state government websites in California, Maryland, Illinois, Texas and New York. Some of the activity could not be definitively tied to OpenAI, the group said. In several cases, the models appeared to use websites in unintended ways and, at times, breached clearly stated usage rules.
OpenAI said most of the activity it has examined involved ordinary research assignments. In those cases, the agents retrieved publicly available online material—including information from government websites considered reliable sources—to answer questions.
The disclosures add to a series of recent reports from technology companies about AI models acting unpredictably or attempting to access other organizations’ websites and systems. OpenAI said in July that two of its most advanced models were behind a cyberattack aimed at AI startup Hugging Face.

