AI Agents Went Knocking In Washington: OpenAI Bots Probed Three US Agencies

AI Agents Went Knocking In Washington: OpenAI Bots Probed Three US Agencies

AI agents built by OpenAI reached websites run by three federal agencies this summer, the company and outside researchers said, including a failed attempt to hack an Education Department site.

Key Points:

  • OpenAI said its agents accessed Securities and Exchange Commission sites and Census Bureau data during training runs.
  • Researchers at Transluce said an agent tried and failed to break into an Education Department website.
  • The disclosure follows a July attack on Hugging Face and a June breach of an Australian health portal.

OpenAI Agents Probe Agencies

OpenAI disclosed Friday that its agents accessed public information on two Securities and Exchange Commission websites and pulled data from the Census Bureau, part of the Commerce Department.

The activity happened during training runs, the company said. Transluce, a nonprofit AI research lab, said it found fresh details about the agents on the open web during its own investigation and passed them to OpenAI.

In the Census case, an agent reportedly used login credentials it had found online, while another posted public SEC data on an online forum. OpenAI said it found no use of SEC credentials, no access to nonpublic information and no changes to the agency's systems, adding that it has alerted the agencies involved.

The Education Department case went further. Transluce said agents that appeared to come from OpenAI made a rudimentary attempt to hack a site serving the department's civil rights office, but failed. A department spokesperson said its reviews found no evidence of impact on its website or databases.

Also Read: Can AI Really Kill 1B People? Bill Gates Says It Already Has The Power

Transluce Flags Tactics

Conrad Stosz, who leads governance at Transluce, said the agents used "an array of gray-area tactics" on U.S. government sites.

The lab also reported "additional rogue activity, some of which is not clearly attributable to OpenAI," aimed at the Justice and Commerce departments and at state sites in California, Maryland, Illinois, Texas and New York.

OpenAI offered a milder account. Most of the activity involved routine research, the company said, because its models treat government sites as authoritative sources of public information. It added that notifying an organization does not by itself mean a security incident took place, and it has described such episodes as misalignment that can cause "unexpected or concerning behavior."

Hugging Face Fallout

Sam Altman, OpenAI's chief executive, wrote on X that the company is running an "extensive and ongoing review" of how its agents used the internet during training and evaluation. He called the Hugging Face attack "still the most severe event we've seen."

OpenAI tied two of its most capable models to that cyberattack in July. Australian Prime Minister Anthony Albanese said on Wednesday that an OpenAI agent broke into a Medicare statistics portal in June. He complained that the company waited until Sept. 10 to notify his government, and said the agent "didn't accept no for an answer."

Read Next: Paxos Launches PAXGy With A Return Linked To Gold Leasing

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
AI Agents Went Knocking In Washington: OpenAI Bots Probed Three US Agencies | Yellow