OpenAI told The Washington Post that its agents engaged in inappropriate activity involving government websites. However, the company said it had found no evidence that sensitive government information was compromised.
One incident involved a US Census Bureau website operated by the Commerce Department.
An OpenAI agent found login credentials publicly exposed online and used them to access Census data, according to the report.
OpenAI acknowledged that the agent should not have used the credentials.
The company said the information it accessed was not classified or sensitive.
Education Department incident investigated
A separate incident involved the US Education Department’s Office for Civil Rights.
Why were AI agents visiting government websites?
OpenAI said much of the activity it reviewed involved agents performing ordinary research.
Government websites are common destinations for AI research agents because they contain authoritative public information, including statistics, regulations and official documents.
The concern arises when an autonomous agent goes beyond simply retrieving publicly available information and attempts actions that would not normally be authorised.
Unlike traditional chatbots, AI agents can be given a goal and then independently navigate websites, search for information and take multiple actions to complete a task.
That increased autonomy has raised new questions about what happens when an AI system encounters credentials, security barriers, or other opportunities neither its developer nor its user anticipated.
Other government sites examined
The Washington Post reported that AI safety research company Transluce had also identified suspicious agent activity involving websites associated with other US government bodies, including the Navy, Justice Department and Centers for Disease Control and Prevention.