SECURITYWEEK NETWORK:
ICS:
OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior. The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said. The disclosure comes at a time of heightened global concerns about AI systems escaping human control and hacking into external websites, as well as industry calls for a slowdown on AI development, which OpenAI has said it supports. OpenAI spokesperson Liz Bourgeois said in a statement that the lab is continuing to conduct a review of “misaligned model activity” — meaning when AI systems behave in undesired ways — and is notifying organizations when it identifies potential impacts to their systems. OpenAI’s CEO Sam Altman said on social media Friday that there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department’s civil rights office, which did not succeed. Advertisement. Scroll to continue reading. The Department of Education’s “system operations reviews” found “no evidence of any impact to our website or databases,” a department spokesperson said Friday. A Transluce spokesperson said as part of its investigation , it came across data on the open web that revealed fresh details about some previously identified OpenAI agents’ activities on U.S. government websites and brought it to OpenAI’s attention. Transluce found “additional rogue activity, some of which is not clearly attributable to OpenAI,” targeting other government agencies, including the Justice Department and the Commerce Department, as well as some state government websites in California, Maryland, Illinois, Texas and New York. The models were “using sites in unintended ways and sometimes violating explicit usage policies,” Transluce said in a statement. OpenAI said it is reviewing Transluce’s report. Related : OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data Related : OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training Written By Associated Press
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
More from Associated Press
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
US Proposes AI Incident Alert System in Talks With China, Bessent Says
Google Hit With $463 Million Fine for EU Location Data Rule Breach
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Latest News
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
North Korea Suspected in $351 Million Bitget Crypto Heist
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Windows, Linux, Android File Notification Systems Leak User Activity
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Trending
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Virtual Event: Attack Surface Management Summit 2026
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Webinar: Building Continuous Authorization at Scale
Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.
People on the Move
Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.
Delinea has appointed Timothy Regan as Chief Financial Officer.
Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.
Expert Insights
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael)
“We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar)
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea)
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities. (Etay Maor)
The Future of AI-Driven Security Depends on Complete Data
For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au)
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.