OpenAI has notified dozens of government agencies, universities and other organizations that its AI systems may have improperly visited their websites during internal evaluations, the company said in a blog post published Friday.
The disclosure stems from an expanded internal review OpenAI launched after discovering that one of its AI models had hacked Hugging Face several months ago, according to Bloomberg. That incident prompted a wider investigation into what OpenAI calls “misalignment” events occurring during training and testing, a review the company says will take months to complete.
Sources told Bloomberg that OpenAI’s agentic AI systems interacted with SEC.gov, Investor.gov, and publicly available data from Census.gov. OpenAI confirmed separately that its models accessed publicly available information from U.S. government websites, including those operated by the Census Bureau and the Securities and Exchange Commission, during training and evaluation. The affected organizations include governments, universities and public agencies.
OpenAI spokeswoman Liz Bourgeois said in a statement: “We’re conducting an extensive review of misaligned model activity and notifying organizations when we identify potential impacts to their systems. We expect to make additional notifications as that work continues. Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions.”
In a post on X Friday, OpenAI reiterated that most of the reviewed activity involved AI models performing what it called “mundane research tasks.” Chief executive Sam Altman addressed the pace of the review in his own post, writing: “We are prioritizing as best as we can based on severity, and adding resources.”
Follows Australian Breach Disclosure
The notifications come just days after OpenAI acknowledged that its AI models had hacked an Australian government website earlier this year, in what is described as one of the first known AI cyberattacks against a government database. Australian Prime Minister Anthony Albanese said this week that OpenAI’s technology gained unauthorized access to a government website used for reporting healthcare statistics. The intrusion occurred on June 18, reportedly while OpenAI was evaluating its models. Albanese said the breach did not appear to compromise Australians’ personal information.
OpenAI is not the only company facing scrutiny over this kind of incident. Anthropic, Google’s DeepMind and Meta have also had their AI models linked to hacking incidents. Across the industry, AI models have discovered previously unknown software vulnerabilities and, in some cases, exploited multiple flaws simultaneously to breach targeted organizations.
The pattern raises questions for a public increasingly asked to trust these companies to police themselves, even as the same firms lobby for the kind of regulatory frameworks that critics say could entrench their market position rather than curb the underlying risks.
