© 2026 WRVO Public Media
NPR News for Central New York
Play Live Radio
Next Up:
0:00
0:00
0:00 0:00
Available On Air Stations

OpenAI says its AI agents probed federal websites without the company's knowledge

DEBBIE ELLIOTT, HOST:

From the White House to Wall Street to the water cooler, the talk of the town is artificial intelligence, how it's transforming our lives and the existential risk it potentially poses. Today, we have new reports of OpenAI agents acting in unexpected ways. This time involves websites of U.S. government agencies. We're joined by NPR's Huo Jingnan to explain more. To start, tell us exactly what happened here.

HUO JINGNAN, BYLINE: According to OpenAI, its agents did things with U.S. government websites that people didn't necessarily want them to. In one case, AI agents took public data from the Securities and Exchange Commission and posted it on another website. That was not part of the assignment. And in another case, AI agents accessed data from the Census Bureau's website after they found credentials that had been posted online.

It's important to note that in both cases, AI accessed publicly available information. It's not hacking, per se, but not ideal behavior from an agent. Separately, research organization Transluce said it has found that agents appearing to belong to OpenAI, quote, "attempted a rudimentary hack on a Department of Education website, which did not succeed," end quote. OpenAI said it's looking into this finding.

ELLIOTT: Do we know when this happened and why the company is telling us about it now?

HUO: We don't really know when these agents accessed these government websites, but OpenAI said the company found out about these incidents during its internal review after a high-profile incident this summer, when its AI agents hacked another company called Hugging Face.

More broadly, OpenAI said it's notified dozens of organizations about activity involving what it calls misaligned AI agents during training and evaluation - basically, when AI systems acts in ways developers don't expect and didn't ask for. Outside researchers I talked to in the wake of the Hugging Face hack said that the top AI company could have caught such incidents much sooner if it had monitored the agents more closely, but for whatever reason, OpenAI didn't do that.

ELLIOTT: Now, what about the U.S. agencies that were affected? What are they saying about this?

HUO: The SEC said no non-public information has been accessed, and the Department of Education said they have found no impact, and the Census Bureau did not respond to NPR's requests for comment.

ELLIOTT: How serious are these incidents compared to, say, that Hugging Face hack that we've been hearing so much about and that has everyone questioning what kind of guardrails should be placed on AI?

HUO: In short, they are not as serious. Unlike the agents in the Hugging Face attack, these agents were given access to the internet. They didn't break out of containment. And unlike the Hugging Face attack, so far, these agents have not succeeded in accessing any information that's been locked away. But they do add to a string of incidents in which agents behaved in ways that people didn't expect to or would like them to, although the severity of the incidents varied.

ELLIOTT: And I guess the most important question here is, what, if anything, is OpenAI doing about this?

HUO: OpenAI says it's just hard to make sure its AI systems don't misbehave. The company describes it as an unsolved problem at this point. This does raise the question of whether OpenAI can train its AI systems sufficiently, and it raises questions about the company's ability to catch and stop misbehavior by its agents. The company says it will publicly disclose examples of major misbehavior, but that suggests that OpenAI may not disclose all of them.

ELLIOTT: That's NPR's Huo Jingnan. Thank you for your reporting.

HUO: Thank you. Transcript provided by NPR, Copyright NPR.

NPR transcripts are created on a rush deadline by an NPR contractor. This text may not be in its final form and may be updated or revised in the future. Accuracy and availability may vary. The authoritative record of NPR’s programming is the audio record.

NPR National Correspondent Debbie Elliott can be heard telling stories from her native South.
Huo Jingnan is a reporter for NPR.
Recent cuts to federal funding are challenging our mission to serve central and upstate New York with trusted journalism, vital local coverage, and the diverse programming that informs and connects our communities. This is the moment to join our community of supporters and help keep journalists on the ground, asking hard questions that matter to our region.

Stand with public media and make your gift today—not just for yourself, but for all who depend on WRVO as a trusted resource and civic cornerstone in central and upstate New York.