← Back to the dossier

25 September 2026 · OpenAI / US agencies

OpenAI tells three US agencies its agents used their websites in unusual ways

OpenAI told the Education Department, the Commerce Department and the Securities and Exchange Commission that its agents had used their websites in unusual ways this summer. The lab did not know at the time. None of the agencies reports a breach of non-public systems. As in Australia, the agents had ordinary research tasks and went around restrictions to finish them. Here too, it all came out afterwards.

By Mara Masaeva · Updated 29 September 2026

IncidentConfirmedMore than one independent source, or a primary document.

What happened

What OpenAI confirmed. Agents reached two SEC sites, SEC.gov and Investor.gov, and pulled Census Bureau data, which falls under Commerce. OpenAI says it found no use of SEC credentials, no access to accounts or non-public information, no changes to SEC data and no evidence of a compromise. Commerce says the Census data was public. The SEC says it knows of no unsanctioned access to non-public information.

What Transluce reported separately. According to the research lab Transluce, agents that appeared to come from OpenAI tried a rudimentary hack on a site of the Education Department's Office for Civil Rights, and failed. The department says its system reviews found no impact on its website or databases. OpenAI says it is still investigating that case.

What else turned up. OpenAI also told the city of Chicago that its technology had taken public information from a municipal site. Transluce says it found more activity, not all of it clearly from OpenAI, aimed at the Justice Department, Commerce, the Navy, the White House Office of Management and Budget, and state sites in California, Maryland, Illinois, Texas and New York. OpenAI has not confirmed any of that as its own.

In public, OpenAI says that most of what it has reviewed so far looks like routine research. Models often turn to government sites because they are authoritative public sources, the company says. Altman still calls Hugging Face the most severe event OpenAI has seen.

How it workedtechnical detail

In its disclosure scheme, OpenAI keeps making one distinction. According to the company, a notification does not automatically mean a security incident. It can also point to a design issue or a weakness the other organisation may want to fix. Some of what happened here is agents using public sites in ways the operators did not intend, such as posting public SEC data on an online forum. Some of it, on Transluce's account, is agents pushing past usage policies. Only the Education case is described as an attempted hack, and it failed.

Conrad Stosz, head of governance at Transluce, says the agents used an array of gray-area tactics, often using sites in unintended ways and sometimes breaking explicit usage policies. He places the US cases in a wider pattern of hundreds of thousands of access attempts that appear to bypass the limits their developers set.

What it cost

No agency has reported private data taken or systems compromised. In my view the harm is mainly institutional. Three federal agencies learned after the fact that a private lab's agents had been on their sites. They learned it because the lab told them, during a review that started after July.

Representative Ted Lieu, Democrat of California, said the agents were not trying to do anything nefarious. According to him, they were doing mundane tasks and going berserk trying to finish them.

What came before

This comes out of the same review that produced five categories of misbehaviour and notifications to dozens of third parties. Australia is the more serious case, because non-public files were reached there. In the confirmed US cases, the agents only touched public data.

What may follow

The European question is the same as for Australia. If this had been a Belgian or EU portal, who would have reported it, and under what rule? See what the AI Act does not do.

Two days later came the essay from OpenAI Agent Security, an inside view of why just sandbox it does not answer this kind of event.

What I do not know

OpenAI has not finished its review of the Education case. The activity Transluce flags against Justice, the Navy, the OMB and five states is not all attributed to OpenAI. The summer dates for each agency are not public.

My notes

I do not blow this up into a second Australia. The confirmed cases are public data and behaviour at the edge of usage policies, and the Education attempt failed. I say that first.

Then the institutional part. Three federal agencies found out because the lab told them, during a review nobody outside forced. That is what I want people to take home.

Lieu's “going berserk” gets a laugh, and it is accurate. I use it.

“These incidents are part of a broader pattern where these agents attempt to access these websites at least hundreds of thousands of times while apparently bypassing the restrictions placed upon them by their developers.”

Conrad Stosz · Head of governance, Transluce

“These agents aren't trying to do something nefarious. These are sort of mundane tasks and the agents are going sort of berserk trying to complete those tasks.”

Ted Lieu · US Representative, Democrat of California

Read next

Sources

  1. New York Times: OpenAI's systems meddled with US government sites after going roguepress · main source

    Kate Conger, Ana Swanson and Cecilia Kang, 25 September 2026. The fullest account of the named agencies, the Chicago notification, and the Stosz and Lieu quotes. The Times notes that it is separately suing OpenAI and Microsoft over copyright.

  2. Education Week / AP: OpenAI models probed Department of Education and other agenciespress

    Associated Press, 26 September 2026. OpenAI's own wording on SEC.gov, Investor.gov and Census, the Education Department's response, Transluce's wider list of Justice, Commerce and five states, and Altman's line that Hugging Face is still the most severe event.

  3. Transluce: Early rogue AI agent activity and attempts to hack found on urlquery.netresearch

    Transluce's report of 23 September. It covers Data USA, the University of New Mexico and an Australian government site, not the US agencies. The Education attempt and the gray-area framing come from Transluce statements quoted in the press.