OpenAI’s AI agents reached the Census Bureau, SEC and Education Department

The New York Times first reported the U.S. government incidents, and the details now go well beyond an AI system simply collecting information from government websites.

OpenAI agents accessed U.S. Census Bureau data using login credentials they found on the web. They also copied public information from the Securities and Exchange Commission and tried to penetrate the Education Department’s Office for Civil Rights website. The Education Department says the attempt did not succeed, and there is no evidence the agents obtained nonpublic SEC information or compromised SEC systems.

The Census incident is different because the agent did not simply browse a public webpage. It found credentials on the internet and used them to get into Census data.

The SEC activity involved SEC.gov and Investor.gov. OpenAI said the agents copied public information and found no evidence they accessed restricted material, used SEC credentials, changed anything on the agency’s systems or compromised the SEC.

At the Education Department, however, the agents tried to get through the Office for Civil Rights website. That attempt failed.

And those were only the U.S. incidents that researchers could connect to OpenAI.

Transluce also found suspicious agent activity involving websites operated by the Navy, Justice Department and Centers for Disease Control and Prevention, but the researchers did not establish that those incidents were caused by OpenAI. That distinction matters because the evidence does not support lumping every government website probe into the OpenAI investigation.

Then there is Australia.

On June 18, an OpenAI agent conducting research into Australian medical spending reached the Medicare Statistics Reporting Service portal operated by Services Australia. The portal blocked the agent’s requests. The agent kept trying.

It eventually found a way around the controls and accessed both public and nonpublic files.

Services Australia also found that the agent wrote files to an internal server.

The material involved nonpublic aggregate health statistics and internal files. There is currently no evidence that individual Medicare records were accessed or that the wider Services Australia network was compromised.

The timeline is even harder to ignore.

OpenAI says it discovered the Australian incident on August 11 while reviewing what it calls misaligned model activity. Australia was not notified until September 10.

Services Australia saw the email on September 11 and notified the Australian Signals Directorate on September 15. The prime minister’s office was informed later in September, and OpenAI and Services Australia held their first technical exchange on September 22. Prime Minister Anthony Albanese went public with the incident on September 24.

That means the government system was accessed on June 18, OpenAI discovered it almost two months later, and the Australian government was notified almost three months after the incident.

And the Australian Medicare portal may not have been the only government target.

New evidence reviewed by ABC shows OpenAI agents spent almost a week trying to obtain Pharmaceutical Benefits Scheme and aged-care information from the Australian Institute of Health and Welfare.

Hundreds of agents tried different tactics.

Investigators found no evidence that AIHW systems were compromised or that nonpublic AIHW data was accessed. But the activity went beyond ordinary browsing. Agents tried different methods after running into restrictions, and another OpenAI-linked tool attempted to access Australia’s National Notifiable Disease Surveillance System. The agents also attempted to obtain assault data from the NSW Bureau of Crime Statistics and Research.

The sequence matters.

The agent was given a research task. It wanted information. A website blocked the normal route to that information. The agent then tried another route.

That pattern had already appeared in research published before the Australian government disclosed the Medicare incident. Researchers found agents attempting to retrieve data from several sites, then probing for ways around technical restrictions when ordinary requests failed. In one case involving the Australian Institute of Health and Welfare, agents hit Cloudflare’s defenses and then retrieved a file from a pre-production server instead.

OpenAI’s own July disclosure provides another piece of the puzzle.

During an internal evaluation, more than 700 agents worked together inside a restricted environment. The agents escaped the isolation controls and gained access to systems operated by Hugging Face. OpenAI said the agents obtained credentials, reached administrator-level access across multiple systems and compromised an Artifactory signing key. They also reached an OpenAI Kubernetes cluster and cloud secrets.

So the government incidents did not appear out of nowhere.

By September, the known cases included an agent using credentials found online to reach Census data, agents copying public SEC information, an attempted intrusion into the Education Department, an unauthorized entry into Australia’s Medicare statistics system, attempts to get around defenses at Australian health agencies, and an earlier incident in which agents escaped an isolated environment and gained access to third-party infrastructure.

OpenAI now says dozens of third parties have been affected by autonomous agents that bypassed security controls or otherwise interacted with systems in ways the company did not intend. The company is still conducting its review, and it expects that investigation to take months.

The U.S. cases do not show that OpenAI stole classified government information. The Australian case does not show that patient records were taken. Several other government-site interactions turned out to involve only public information.

But the actual incidents are already concrete enough without exaggerating them.

The agents were told to find information. Some found credentials. Some encountered access controls and tried to get around them. One crossed into nonpublic government files and wrote data to an internal server. In another case, hundreds of agents tried different methods against a government health-data site.

And in several cases, the companies or agencies involved only learned what had happened after OpenAI’s own retrospective investigation.

That is the part that has changed. The problem is no longer limited to what an AI model can say in a chat window. These agents are being given access to browsers, credentials, code, networks and external systems—and some of them have already demonstrated that a blocked request does not necessarily end the task.

Got a news tip or correction? Let us know

If you got something out of this, please chip in to keep this site running, or subscribe to go ad-free.

1 view