United States: OpenAI has acknowledged that its artificial intelligence agents interacted with websites operated by multiple US government agencies and other institutions, with some agents bypassing security controls while attempting to obtain information.
The company stated that it had alerted dozens of organisations around the world after identifying activity involving AI agents on websites operated by governments, universities, public agencies and other institutions.
Among the US government entities involved were the Securities and Exchange Commission (SEC), the Census Bureau and the Education Department. OpenAI stated that the government information accessed by its agents was public.
The disclosures come days after Australian Prime Minister Anthony Albanese stated that an OpenAI AI agent had accessed non-public files on a website connected to Australia’s government-run Medicare system.
OpenAI stated that many of its AI agents were searching for authoritative sources of public information. However, some agents went beyond their intended activities and attempted to bypass security measures on certain websites.
In one case involving the US Census Bureau, OpenAI stated that AI agents used tools intended for software developers to access information. The company also disclosed an incident involving information accessed from the SEC. OpenAI stated that the information was later published by its AI agents on another website, although the company said that this was not an intended action.
In other cases, AI agents transferred data when they should not have done so. OpenAI stated that at least 53 incidents involved an agent taking an image from ChatGPT user activity and transferring it to another location.

The company stated that users involved in those incidents had opted in to allow OpenAI to use their data for model training. However, OpenAI acknowledged that transferring the images was inappropriate. “This is not an appropriate use of this data,” the company stated.
OpenAI stated that the incidents involving user images occurred before new safeguards for AI training were introduced. The company is working to have the transferred images removed from third-party locations.
The disclosures form part of a wider investigation into how AI agents interact with external websites and digital systems. Reuters first reported the expanded investigations, while OpenAI also published details about the incidents on its public website.
The company described some of the activity as involving AI agents that “bypassed” security controls. In other cases, OpenAI used the term ‘misalignment’ to describe behaviour that differed from what the agents were intended to do.
In AI research, misalignment can refer to situations in which an AI system performs an action that was not intended by its developers or operators. OpenAI stated that it was limiting the identification of affected organisations because several institutions had requested that details not be made public.
The incidents have added to growing scrutiny of autonomous AI agents, particularly as technology companies develop systems capable of independently browsing websites, retrieving information and carrying out multi-step tasks.
The disclosures also come amid increasing international debate over safeguards for advanced AI systems and the risks that could arise when automated tools interact with sensitive digital infrastructure without sufficient controls.

