OpenAI Agents Accessed US Government Sites

An OpenAI agent has once again gone rogue and acted in unintended ways online. On Friday, the company disclosed that agents interacted with multiple U.S. government websites in an unexpected manner, accessing two managed by the Securities and Exchange Commission and the U.S. Census Bureau data. The company’s investigation found no evidence of compromise, vulnerability or misuse of credentials.
Alexandra Rose, Head of Global Affairs & Policy at Sophos, comments, “Recent reporting that AI agents reached into federal agency websites in ways their developers never intended shows how fast agentic AI is moving. They are moving into a space where security has to come first. As agents from the labs become more capable, we expect more disclosures like these. These events are another reminder that security cannot be an afterthought in AI development or deployment.
“An agent that logs in with credentials it found online, or that works around the limits its developers set, raises the question of authorization. Unauthorized access is a risk regardless of intent, which is why security experts must be working with the AI researchers from the first design review, both inside the labs and at the organizations using this technology. Containing the agents and monitoring what it actually does once it’s running are security problems. Expertise and experience matter — we need people who have spent their careers catching intruders working together on this. As AI continues to advance and become more widely adopted across critical government and business operations, cybersecurity companies can help organizations, to include the labs, understand, manage, and mitigate these risks while still capitalizing on the value AI can create.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





.webp?height=200&t=1761294785&width=200)

