OpenAI models took unapproved actions on two U.S. government websites, the company found during a review of model activity. Another model attempted to hack into a third, according to independent AI research firm Transluce.
"Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions," an OpenAI spokesperson told USA TODAY. "Some involved government websites because our models often turn to them as authoritative sources of public information.”
Models accessed publicly available information on the Security and Exchange Commission website. OpenAI said they found no evidence of a compromise or vulnerability. The company notified the U.S. government because the models posted some
of the information on a separate public website, which they consider misalignment, or mismatched intent of the human prompt compared with the action the model took.
Another misaligned model also accessed some publicly available U.S. Census Bureau data while completing internal training tasks, OpenAI said. During the internal review, they found that a model accessed a leaked API key — a digital identifier that authorizes communication between software applications — that was available on a public platform. The key was not used to access Census accounts or modify data.
OpenAI models also tried and failed to hack into the Education Department's website, according to a report from Transluce.
The incidents were first reported by The New York Times.
“The Department of Education’s system operations reviews have found no evidence of any impact to our website or databases," an Education Department spokesperson told USA TODAY.
An SEC spokesperson told USA TODAY no non-public information was accessed.
USA TODAY has reached out to the Commerce Department.
"We have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations," OpenAI CEO Sam Altman said in a post on X on Sept. 25.
The company distinguished the three instances from a high-profile incident of OpenAI's technology going rogue this summer when a swarm of agents hacked AI start-up Hugging Face in July. In these cases, rather than the training model breaking out of a secure environment to hack into a private website, the models either failed at doing so or only accessed public information.
"We initially understood the Hugging Face incident primarily as a security issue, since it involved a platform-level compromise. It remains the most severe activity of this kind that we have identified from our models to date, and it was driven primarily by a highly capable, internal-only research model," OpenAI said in a blog post Sept. 25.
The news comes two days after Australian prime minister Anthony Albanese said OpenAI agents hacked into an Australian healthcare database. He called it "unacceptable."
Greta Reich covers the artificial intelligence industry for USA TODAY through a fellowship from the Tarbell Center for AI Journalism. Funders do not provide editorial input.
This article originally appeared on USA TODAY: OpenAI agents accessed US government websites, tried to hack one













