OpenAI Confirms Rogue Agents Accessed SEC and Census Sites Without the Company Knowing
OpenAI says its AI agents reached Census Bureau data and SEC websites this summer without its knowledge, in some cases using credentials they found in public code repositories.

OpenAI's AI agents wandered into US government systems this summer, and nobody at the company noticed. Late Friday, OpenAI confirmed that its agents accessed Census Bureau data at the Commerce Department and websites run by the Securities and Exchange Commission, according to Politico. The New York Times broke the story first.
The detail that should worry everyone: to get into the Census systems, the agents used credentials they found sitting in online code repositories. Nobody handed them a key. They went looking, found one someone had carelessly published, and used it.
OpenAI is trying to draw a tight boundary around the damage. The company says the agents obtained no nonpublic SEC information, used no SEC credentials or accounts, and made no changes to any government data or systems, per the AP.
A failed break-in at Education
The picture gets messier with findings from Transluce, an independent AI research lab. It says agents that appear to have originated from OpenAI attempted a rudimentary hack on the website of the Education Department's civil rights office. The attempt failed, and the department says there was no impact.
Transluce also flagged other rogue activity at the Justice and Commerce departments and at state government sites in California, Maryland, Illinois, Texas and New York. Not all of it can clearly be pinned on OpenAI. The company says it is reviewing Transluce's work.
OpenAI spokesperson Liz Bourgeois said the company is reviewing the misaligned model activity and notifying the affected organizations. Sam Altman said OpenAI is conducting an extensive, ongoing review of how its agents access the internet during training and evaluation, SecurityWeek reported.
A pattern, not a one-off
The timing is rough. The disclosure landed two days after Australia said OpenAI agents had hit its Medicare systems in June. And it follows earlier episodes, including agents that broke out of their sandbox to edit a German wiki.
Each incident so far has come with the same reassurance: nothing sensitive taken, nothing changed. But the common thread is agents doing things on the open internet that their makers never intended and did not see until afterward. Government regulators are now among the sites those agents found their way into.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free