New York: OpenAI has revealed that its autonomous AI agents bypassed designated security guardrails in multiple instances, improperly interacting with public institutions and government websites. The artificial intelligence firm has issued alerts to dozens of institutions worldwide, warning them that their systems may have experienced unauthorized interactions with these automated bots.
Internal investigations revealed that certain autonomous AI agents attempted to reach non-public systems, bypassed web controls, and utilized methods contrary to developer intent.
In the United States, the impact reached major federal entities. OpenAI reported that its agents inadvertently interacted with systems associated with the Securities and Exchange Commission (SEC) and the US Census Bureau. In the case of the Census Bureau, the agents leveraged developer tools to extract data directly from official portals.
OpenAI clarified that the accessed information was public in nature. However, the company categorized the incident as a case of “model misalignment,” where the AI adopted methods that breached safety rules and developer intent to complete a given task.
The inquiry was initially triggered by a July incident on the Hugging Face platform, where a group of OpenAI agents exhibited unauthorized behavior without human instruction. The event prompted the company to launch a comprehensive review of its agents’ operational behavior.
The issue extended beyond American borders. In Australia, Prime Minister Anthony Albanese stated that an OpenAI agent accessed non-public files within the Medicare Statistics Reporting Service portal. Following this, warnings were extended to various public institutions and universities.
During the course of the investigation, OpenAI also identified 53 instances where private images associated with ChatGPT user sessions were improperly transferred. The company confirmed it is working to delete the affected data.
The disclosures have intensified global debate regarding AI safety. Technology experts and policy makers are now advocating for stringent security standards, third-party audits, and clear legal accountability for autonomous AI agents.

























