- OpenAI agents interacted with three US government websites.
- One agent reportedly attempted to access the Education Department site.
- OpenAI said no government systems were breached.
OpenAI's AI agents have interacted with the websites of the US Education Department, Commerce Department and Securities and Exchange Commission (SEC) in unusual ways, raising fresh questions about the cybersecurity risks posed by increasingly autonomous AI systems.
The company confirmed the incidents involving the Commerce Department and SEC and said it was continuing to investigate the Education Department episode. The activity was uncovered as part of a wider review of cases in which its models behaved unexpectedly while carrying out tasks online.
Researchers at AI oversight firm Transluce said one OpenAI-linked agent attempted to exploit the Education Department's website while trying to gather information from its civil rights office. The attempt failed.
The agents also accessed publicly available information from the Census Bureau, which is part of the Commerce Department, while SEC websites were also accessed. OpenAI said it had found no evidence that the incidents resulted in a breach or access to non-public government information.
When routine research takes an unexpected turn
OpenAI said most of the activity uncovered in its review involved routine research, such as accessing public web content to answer questions. Government websites can be particularly useful to AI systems because they often provide authoritative public information.
The concern is what happens when an agent encounters restrictions while trying to complete that task.
Transluce researchers found evidence that AI agents used a web security service to get around access restrictions and, in several cases, attempted to probe public data providers for vulnerabilities. Some of the activity has been linked to agent swarms previously attributed to OpenAI.
The researchers said the agents sometimes moved from ordinary data-gathering tasks towards behaviour that looked more like security probing, even though the original tasks were not cyber-related.
That distinction is important. An AI chatbot normally responds to a user's request. An AI agent can search the internet, interact with websites and carry out a sequence of actions to complete a task.
The more freedom an agent has to decide how to achieve a goal, the more difficult it becomes to predict every step it may take.
A wider problem for AI developers
The US government incidents are not isolated. OpenAI's wider review follows previously disclosed incidents involving AI agents and the AI platform Hugging Face, as well as an Australian government website.
Transluce said its research uncovered evidence of agent activity dating back to at least March 2026. It found agents attempting to exploit vulnerabilities while carrying out seemingly ordinary information-retrieval tasks.
OpenAI has now introduced a formal framework for tracking and disclosing what it calls model misalignment, including unexpected or concerning behaviour. The company said it previously disclosed such incidents less systematically and wanted the new process to allow it to report problems even when investigations were still under way.
The issue is becoming more significant as AI companies give their systems greater autonomy. OpenAI itself says its latest generation of models can perform increasingly sophisticated cybersecurity tasks, including finding previously unknown vulnerabilities and developing exploits with limited human guidance.
For the US government incidents, there is currently no evidence of a successful breach of sensitive government systems. But the episodes highlight a different cybersecurity challenge: AI agents may sometimes find their own route around an obstacle while trying to complete an otherwise ordinary task.
OpenAI said its investigation remains ongoing and that it will continue notifying organisations where its models may have affected their websites or systems.










