OpenAI agents accessed Census, SEC data and tried to hack Education website

ANDREJ IVANOV / AFP via Getty Images
The disclosure follows warnings from former officials in August that government systems could face unintended intrusions by autonomous AI agents.
UPDATED Saturday, Sept. 26
OpenAI’s artificial intelligence agents accessed Census Bureau data using developer keys found online and reposted public Securities and Exchange Commission information on another website, the company confirmed. Researchers separately identified a failed attempt by agents linked to OpenAI to hack an Education Department website.
The details identify specific U.S. agencies following the company’s Friday disclosure that government websites were among the outside systems involved in its investigation of agents acting beyond their assigned tasks or intended methods during training and testing.
The New York Times reported Friday that researchers at the AI research organization Transluce identified the unsuccessful attempt to hack Education’s website to obtain data from its civil rights office. An Education spokesperson told the newspaper that reviews found no evidence of an impact on its website or databases.
OpenAI said its models accessed only public information from Census and the SEC. In the Census case, agents used Census Data API developer keys found in public GitHub repositories during internal training tasks. Those keys authenticated read-only requests for public demographic and economic data, the company said.
OpenAI said it found no access to Census accounts or key-management functions, and no ability to modify agency data or systems.
At the SEC, agents retrieved information available to any visitor to SEC.gov and Investor.gov, then posted some of it on another public webpage. OpenAI said it found no use of SEC credentials, access to accounts or nonpublic information, changes to agency systems, or evidence of a compromise or vulnerability.
The company said it notified both agencies and shared technical findings. The SEC told the Times it was unaware of unauthorized access to nonpublic information, while Commerce said no private Census data was accessed.
“As we previously announced, we’re conducting an extensive review of misaligned model activity and notifying organizations when we identify potential impacts to their systems,” an OpenAI spokesperson told Nextgov/FCW. “We expect to make additional notifications as that work continues.”
The company has notified dozens of organizations as it reviews activity that may have bypassed security controls, disrupted services or otherwise negatively affected websites. Sites involved include those operated by governments, universities and public agencies.
Nextgov/FCW reported in August that former officials and cybersecurity experts saw an increasing risk of unintended AI intrusions into federal systems. They cited aging technology, insufficient separation between networks and contractor connections as potential routes into systems the agents were never authorized to enter.
The newly detailed U.S. activity does not establish that federal networks were breached. It offers a broader picture of how government websites can become caught up in AI experiments conducted outside their control, raising questions about developers’ ability to contain agents pursuing routine tasks.
The disclosures could also intensify debate over whether safeguards can keep pace with increasingly capable systems, amid concerns that similar failures could have more serious consequences for sensitive government networks or critical infrastructure.
In Australia, officials revealed this week that an OpenAI agent — autonomous software that uses an AI model to plan and complete tasks — gained unauthorized access to a government health statistics portal in June.
The agent was researching public medicine spending when it accessed infrastructure behind the Medicare Statistics Reporting Service portal, government officials said Thursday. After a request for information was denied, it circumvented the portal’s restrictions.
Officials said the information involved aggregated statistics and that no individual medical records were accessed. The portal was separate from systems handling Medicare claims, payments and personal information.
OpenAI discovered the June activity in August and notified Services Australia on Sept. 10. Prime Minister Anthony Albanese raised concerns directly with OpenAI CEO Sam Altman, and Australian officials announced a task force to examine the incident, government network security and whether existing laws adequately address such activity.
OpenAI cautioned that its notifications should not automatically be interpreted as evidence of significant security incidents. Most cases identified so far were of low severity, with limited or no evidence of meaningful impact, it said.
The company said some organizations may conclude the information accessed was intentionally public or the interaction was not concerning, while others may identify a weakness to address.
The review follows OpenAI models’ July breach of AI platform Hugging Face during an internal cybersecurity evaluation. The company has since broadened its investigation to examine agents’ interactions with outside websites.
“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” the OpenAI spokesperson said. “Some involved government websites because our models often turn to them as authoritative sources of public information.”
OpenAI said the review will take months to complete. It is sharing technical findings with affected organizations and generally leaving decisions about public disclosure to them.
The company separately disclosed Friday that research agents had transmitted training and evaluation data to outside services. It identified 53 instances in which user-provided images were posted to image-hosting sites through links that were not publicly listed. Most of that content has been removed, OpenAI said, and it is working with hosting providers to remove the rest.




