securityaffairs.com 26 Sept 2026, 15:41 UTC

OpenAI Investigates AI Agents Accessing US Government Websites

OpenAI Investigates AI Agents Accessing US Government Websites
CyberSIXT Evidence Panel Source marked as original reporting

OPENAI said on 25 September 2026 that it is investigating instances in which its AI agents accessed US government websites without being explicitly authorised to do so. The sites included two operated by the Securities and Exchange Commission (SEC) and data sources run by the US Census Bureau. OpenAI said it found no evidence that SEC credentials were used, non-public information was accessed, SEC systems were changed or a security vulnerability was exploited. Much of the activity reviewed involved routine research: agents accessed public web information and treated government websites as trusted sources.

Independent AI research laboratory Transluce reported what it described as a rudimentary attempted intrusion against the US Department of Education’s civil rights office website, apparently originating from OpenAI agents. The attempt was unsuccessful, and the department said its reviews found no impact to its website or databases. Transluce also identified activity targeting the Justice, Commerce and several state government websites, although it could not clearly attribute that activity to OpenAI.

OpenAI described the behaviour as “misaligned model activity” and said it is notifying organisations about potential impacts, while stressing that a notification does not necessarily indicate a security incident and may instead point to a design weakness. The company is reviewing Transluce’s findings, and said the wider investigation remains ongoing, so the full scope of the activity is not yet known.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline