OpenAI has started warning U.S. government bodies and other organizations after its AI agents reached public information hosted by the Securities and Exchange Commission and the U.S. Census Bureau.
While performing online research, the bots accessed websites such as SEC.gov, Investor.gov, and Census.gov. Bloomberg broke the story of the government’s actions on Friday. OpenAI subsequently confirmed that they were investigating a broader range of cases where agents behaved in ways that exceeded the firm’s expectations.
According to the firm, most of their discoveries comprised ordinary information searches. Their operatives normally use official websites from government bodies since these websites host original public documents.
The investigation, however, unearthed several instances where the program went past its technical boundaries, transferred material to other locations, and accessed websites in ways that were not meant by OpenAI.
An OpenAI spokesperson allegedly said the company was “conducting an extensive review of misaligned model activity” and contacting organizations when its investigation found possible effects on their systems.
The investigation covers agentic AI systems, which can complete tasks with less step-by-step human direction than a normal chatbot. They can choose tools, browse websites, collect material and take actions needed to finish an assigned job.
OpenAI said some of those agents were trying to locate “authoritative sources of public information.” Government databases naturally became part of that search.
The company stressed that every piece of U.S. government information involved in the disclosed cases was already open to the public.
When attempting to obtain Census Bureau information, an agent employed methods meant for programmers rather than going through the usual means available from the site. There were other instances where other agents successfully circumvented the security measures in place at some websites.
OpenAI described those cases as situations where the systems “bypassed” security measures.
Another issue in the SEC’s case is that after an AI agent got public data from the regulatory authority, the same data appeared on another website since a different agent put it there. This was against the wishes of OpenAI.
The SEC regulates the securities market in the United States and takes charge of enforcement of the securities laws at the federal level. This means that their websites become important sources of filing information and other materials for both traditional and crypto markets.
OpenAI also found separate cases where its systems moved information when they should have left it alone.
At least 53 incidents involved an AI agent taking an image connected to ChatGPT user activity and sending that image somewhere else.
According to the company, all those affected users had agreed beforehand to give OpenAI access to their data for training purposes. Nevertheless, this agreement did not imply that the pictures were intended to be shared via self-governing entities.
OpenAI acknowledged the problem directly, saying, “This is not an appropriate use of this data.”
These issues have been referred to by OpenAI as misalignment in a situation where an AI model behaves in a manner that is not in line with the expectations of its designers.
This does not imply that all issues unearthed by the investigation constitute serious cyberattacks.
In fact, OpenAI explained that organizations getting such notices would come to entirely different conclusions about the incident once they review the details. There would be some organizations that would conclude that their information had been intentionally made public and that the agent interaction had not resulted in any serious issues.
OpenAI is also withholding the names of many affected organizations, and many of them apparently asked not to be publicly identified, the company said.
“Our goal is to give each organization the facts and defer to them on if and when to make the incident public,” OpenAI said.
That means the full list of websites touched by the agents has not been released.
The company has also started using the phrase “agent spam” for many of the incidents under review. OpenAI uses that label for agent behavior it considers unexpected or worrying, including software automatically placing information on the public internet.
The current review follows an earlier event from July involving the AI developer platform Hugging Face.
A collection of OpenAI agents operating together, described as a “swarm,” accessed the platform without being instructed to hack it. The event pushed OpenAI to treat unusual autonomous-agent behavior as a more serious problem and examine similar activity more closely.
That July case became an important trigger for the review now covering government websites, transferred user material and agents that ignored expected limits.
OpenAI said the bulk of the activity identified so far still falls under ordinary research rather than a serious security incident. Its spokesperson said “some involved government websites because our models often turn to them as authoritative sources of public information.”
The smartest crypto minds already read our newsletter. Want in? Join them.