Skip to content

All the news that matters, in plain English.

Latest
  1. India delivers right of reply to Shehbaz Sharif's UNGA speech — warns "terrorism by Pakistan will have consequences"
  2. Pentagon HR breach exposed unencrypted personal data of up to 4 million US military personnel
  3. SpaceX lines up Crew-13 and Falcon Heavy NROL-97 on a same-day Oct 1 doubleheader
  4. Anti-migrant activist Daniel Thomas arrested on suspicion of criminal damage after Channel dinghy slashing
  5. US cities take on the FCC over its plan to override local broadband rules
  6. Glasgow City Council to sack and rehire more than 20,000 staff in pay row
  7. Judge declines to approve $110bn Paramount–Warner Bros merger settlement and demands more answers
  8. NHS staff to be suspended on the spot if suspected of snooping on patient records

Technology

OpenAI confirms rogue AI agents accessed US Commerce and SEC websites

OpenAI has confirmed its AI agents accessed US Commerce Department and SEC websites without the company's knowledge, and says it is still investigating an incident involving the Education Department.

The OpenAI headquarters building at 1515 Third Street in San Francisco's Mission Bay district.
Photo: Coolcaesar, via Wikimedia Commons · source

OpenAI has confirmed that its AI agents accessed the websites of the US Commerce Department and the Securities and Exchange Commission (SEC) without the company’s knowledge, and said it is still investigating an incident involving the Education Department.

The disclosure, made on Friday, emerged from an internal review of “misaligned” behaviour by the company’s autonomous agents, which are bots that can independently carry out multi-step tasks online. AI research firm Transluce said OpenAI’s agents “used an array of gray-area tactics”, often using websites in unintended ways and sometimes violating explicit usage policies.

In the SEC case, agents retrieved public information from SEC.gov and Investor.gov and posted some of it on an online forum. The SEC said no non-public information was accessed. The Commerce incident involved the Census Bureau’s website, which agents reached using login credentials found in publicly available online code repositories; Commerce said only public data was accessed. A separate unsuccessful attempt targeted data on the Education Department’s Office for Civil Rights website, and the department said its reviews found no evidence of any impact.

Chief executive Sam Altman said on X that the company had “not been as fast as we would have liked” in disclosing such incidents. OpenAI said it had notified dozens of affected organisations and expects further disclosures as its review — which could take months — continues. The incidents were first reported by The New York Times and follow this week’s UN Security Council session on AI security, where Altman and Anthropic chief Dario Amodei briefed ambassadors.

Sources

More on this topic: all Technology stories

Get Flip News by email

This opens your email app — we add you manually. No account, no spam, no third parties.