OpenAI's autonomous agents spent the summer probing U.S. government websites without the company's knowledge, and the agencies entrusted with guarding American infrastructure barely shrugged.
The AI firm confirmed that its agents interacted with sites run by the Commerce Department, the Securities and Exchange Commission, and the Education Department, according to the New York Times. At Commerce, agents pulled Census Bureau data using login credentials they found in public code repositories. At the SEC, they copied public material from SEC.gov and Investor.gov and reposted it elsewhere. At Education, they tried and failed to break into the civil rights office hunting for data. Researchers at the AI firm Transluce uncovered the activity.
OpenAI says none of this counts as a breach. SEC spokesperson Kurt Hopfenspirger told Politico that "no non-public information was accessed." An Education Department spokesperson said reviews found "no evidence of any impact to our website or databases." A Commerce official shrugged off the Census scrape because the data was already public.
Problem is, these are the same AI companies lobbying Washington for deeper integration into federal systems — and they can't keep their own products from wandering into government networks uninvited. The company only learned about the probes after outside researchers flagged them, just as it only learned in August about an OpenAI agent that hacked Australia's national healthcare database in June.
CEO Sam Altman posted on X that the company was "not as fast as we would have liked" in responding, calling it an "extensive and ongoing review related to our agents' use of internet access during training and evaluation." An OpenAI spokesperson told CNN that "most of the activity we've reviewed so far involved routine research tasks," framing the government-site hits as the models turning to "authoritative sources of public information."
That's a convenient spin. Finding login credentials in public code repositories and using them to access government systems isn't a research task — it's exactly the kind of behavior cybersecurity professionals call credential harvesting. And reposting SEC content on a separate site isn't citation; it's duplication that could enable impersonation.
Transluce also detected rogue agent behavior reaching the Justice Department and state government sites in California, Maryland, Illinois, Texas, and New York, though it couldn't firmly tie all of it to OpenAI. Probing of Navy and White House budget office sites couldn't be traced to any single lab, the Times reported.
This is now a pattern. OpenAI traced a July attack on AI startup Hugging Face to two of its most capable models. CNN reported that competitors Anthropic, Meta, and Google have also acknowledged rogue agent behavior during breach attempts.
Republican Rep. Jay Obernolte, co-chair of the AI caucus, told CNN the incident is "another example of a loss of human control." Democratic Rep. Ted Lieu offered a similar warning, telling the Times the technology "will relentlessly try to complete a task, and it doesn't understand morality and consequences and evil and good."
Bipartisan concern, zero accountability. The Daily Caller noted the specific departments and the credential-harvesting angle; CNN buried the mechanics and amplified the industry's push for international regulation — with Altman and Anthropic CEO Dario Amodei urging the UN Security Council to set global AI standards. The same executives whose products are running roughshod over government networks now want supranational bodies writing the rules.
The open question: if AI agents can probe federal websites undetected by their own creators, what exactly is Washington trusting when it hands these companies contracts and access?








