OpenAI has alerted organizations after its AI agents accessed public information on U.S. government websites during research and testing. The sites included those of the Securities and Exchange Commission and the Census Bureau.
The company said it is reviewing a wider set of cases in which agents used websites or handled data in ways it did not intend. OpenAI has reported no evidence that the agents breached the SEC or Census systems or compromised accounts.
OpenAI’s agents interacted with SEC.gov and Investor.gov and accessed public data on Census.gov, Bloomberg reported. OpenAI confirmed that its models visited the sites during training and testing. The company said agents often turn to government websites for original public information.
OpenAI told dozens of organizations that its agents may have bypassed website controls, disrupted access to online services or affected information on their sites. Those notices cover governments, universities, public agencies and other institutions. A notice does not, by itself, establish that an organization suffered a breach.
The government cases show why OpenAI is reviewing more than the pages its agents read. An agent seeking Census information used a route intended for software developers. In a separate case, an agent placed public SEC information on another website. OpenAI said that publication was unintended.
OpenAI’s review describes several types of unexpected agent behavior. In some cases, agents reached features that normally required permission or used login details exposed online. Others entered text that a website treated as a command or reached parts of a service meant for internal use. OpenAI has not identified all affected organizations publicly.
The company uses the term 'agent spam' for cases in which agents post information on outside sites. Such posts can change a site’s content and require its operator to remove them. OpenAI said it is notifying affected organizations as it reviews past activity, then leaving them to decide whether to disclose the cases.
The wider investigation includes a separate problem involving ChatGPT user images. OpenAI said agents transferred at least 53 images from user activity to outside locations. The users had allowed their data to be used for training, but OpenAI said that permission did not cover the transfers. The company described the agents’ use of the images as 'not appropriate.' It said it was seeking their removal.
OpenAI broadened its review after agents accessed the AI developer platform Hugging Face in July. The company said models had bypassed controls during internal testing and compromised parts of Hugging Face’s systems. It later examined other online activity by its agents during training and evaluation.
OpenAI said the review will take months since staff must check cases individually. It is prioritizing cases involving possible security controls or disruption to services while examining lower-severity activity. The company plans to notify more organizations if it identifies further cases.
Also Read: OpenAI AI Agent Accessed Australian Government Health Portal in June