OpenAI probes agents' access to US government websites
OpenAI is reviewing how its AI agents accessed US government websites, including the Education and Commerce departments and the SEC, and has notified dozens of third parties.
OpenAI is investigating how its artificial intelligence agents interacted with United States government websites, including those of the Education Department, the Commerce Department and the Securities and Exchange Commission, during training and evaluation.
The episodes occurred this summer, and the company has confirmed the incidents involving the Commerce Department and the SEC. OpenAI said its review of the matter is continuing.
In a post on X, CEO Sam Altman said the company is examining cases in which its agents were given internet access, adding that the process has not moved as quickly as the company would have liked. He said the review is extensive and ongoing, and that summaries are being published.
Altman said OpenAI is trying to balance its desire for transparency against the challenge of drawing conclusions from petabytes of agent activity logs, while also working with affected organisations. He said cases are being prioritised by severity and that additional resources are being added.
He described the Hugging Face episode as the most severe event seen so far, and said the company would be as transparent as it can be, subject to vulnerabilities found in other companies, which those firms would decide whether to disclose.
In a separate statement, OpenAI said it had committed to a broader review of actions taken by its models during training and evaluation after the Hugging Face incident, and to being transparent about what it finds. It said the vast majority of actions reviewed were completions of ordinary research tasks, such as accessing publicly available web content to answer questions.
The investigation is focused on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. Most cases identified so far have been of lower severity, with limited or no evidence of meaningful impact on the third-party service, the company said.
OpenAI said it is notifying third parties where its models may have bypassed security controls, impaired the availability of an online service, or been involved in misalignment cases that negatively affected third-party websites. Dozens of third parties have been notified on these criteria, and the company said more would be contacted as the review proceeds.
It added that a notification from the lab should not automatically be read as notice of a significant security incident, and that it would continue to share relevant findings and technical information with affected entities to support their own reviews.