OpenAI AI agents meddled with US government websites: report - Communicate Online
Share

OpenAI AI agents meddled with US government websites: report

By Communicate Staff

|

OpenAI’s artificial intelligence agents interacted with and attempted to access several US government websites in unusual ways this summer, without the company’s knowledge at the time, according to a report by The New York Times.

The incidents involved websites of the US Education Department, Commerce Department and Securities and Exchange Commission (SEC), the newspaper reported, citing security researchers and a person familiar with the episodes.

OpenAI confirmed the incidents involving the Commerce Department and SEC and said it was continuing to investigate the Education Department episode. The company said it had recently notified the agencies that its AI agents — software capable of acting autonomously — had interacted with their websites in unusual ways.

According to security researchers at AI research firm Transluce, OpenAI’s technology attempted to hack the Education Department’s website to gather information from its civil rights office but was unsuccessful.

The AI also accessed publicly available Census Bureau information using login credentials it found online, while OpenAI agents separately shared public information from the SEC website on an online forum, the Times reported.

OpenAI said none of the incidents amounted to breaches, describing them instead as examples of its technology behaving in unexpected and concerning ways.

The company discovered the episodes during a broader review of hacking-related activity involving its AI systems. That review followed an attack on an Australian government website in June and an incident involving AI startup Hugging Face in July.

The Times reported that the internal investigation into the Hugging Face incident uncovered the Australian breach as well as at least six other attempted breaches and instances in which AI systems hid mistakes, generated fabricated data and moved files onto the open internet without authorization.

An OpenAI spokeswoman said the company’s review was “extensive” and ongoing. She said much of the activity involved routine research tasks, including accessing public web content, adding that government websites are frequently used by AI models because they are considered authoritative sources of information.

OpenAI CEO Sam Altman acknowledged on social media that the company had not disclosed AI incidents as quickly as it would have liked. He said the company was prioritizing disclosures according to severity and described the Hugging Face breach as the most serious incident identified so far.

The episodes have intensified debate over AI safety and the effectiveness of safeguards designed to prevent autonomous systems from taking unintended actions.

The developments come as Middle Eastern governments and investors, particularly in the UAE and Saudi Arabia, are committing billions of dollars to artificial intelligence infrastructure, models and applications. The UAE has positioned itself as a global AI hub, with state-backed investments spanning data centres, computing capacity and AI companies. The growing deployment of autonomous AI agents therefore has implications beyond technology companies, as governments and businesses in the region increasingly explore AI systems capable of operating with greater independence.