Sept. 25, 2026, 9:44 p.m. ET
OpenAI fashions took unapproved actions on two U.S. authorities web sites, the corporate discovered throughout a evaluation of mannequin exercise. One other mannequin tried to hack into a 3rd, in line with unbiased AI analysis agency Transluce.
“Many of the exercise we’ve reviewed thus far concerned routine analysis duties, reminiscent of accessing public net content material to reply questions,” an OpenAI spokesperson informed USA TODAY. “Some concerned authorities web sites as a result of our fashions usually flip to them as authoritative sources of public data.”
Fashions accessed publicly accessible data on the Safety and Alternate Fee web site. OpenAI mentioned they discovered no proof of a compromise or vulnerability. The corporate notified the U.S. authorities as a result of the fashions posted a few of the data on a separate public web site, which they take into account misalignment, or mismatched intent of the human immediate in contrast with the motion the mannequin took.
One other misaligned mannequin additionally accessed some publicly accessible U.S. Census Bureau information whereas finishing inner coaching duties, OpenAI mentioned. Through the inner evaluation, they discovered {that a} mannequin accessed a leaked API key — a digital identifier that authorizes communication between software program functions — that was accessible on a public platform. The important thing was not used to entry Census accounts or modify information.
OpenAI fashions additionally tried and didn’t hack into the Schooling Division’s web site, in line with a report from Transluce.
The incidents had been first reported by The New York Occasions.
“The Division of Schooling’s system operations opinions have discovered no proof of any influence to our web site or databases,” an Schooling Division spokesperson informed USA TODAY.
An SEC spokesperson informed USA TODAY no private data was accessed.
USA TODAY has reached out to the Commerce Division.
“Now we have not been as quick as we might have appreciated however we try to steadiness our want for transparency with gaining a transparent understanding from petabytes of agent exercise logs, and dealing with impacted organizations,” OpenAI CEO Sam Altman mentioned in a put up on X on Sept. 25.
The corporate distinguished the three cases from a high-profile incident of OpenAI’s expertise going rogue this summer season when a swarm of brokers hacked AI start-up Hugging Face in July. In these circumstances, slightly than the coaching mannequin breaking out of a safe setting to hack into a non-public web site, the fashions both failed at doing so or solely accessed public data.
“We initially understood the Hugging Face incident primarily as a safety challenge, because it concerned a platform-level compromise. It stays essentially the most extreme exercise of this type that we have now recognized from our fashions up to now, and it was pushed primarily by a extremely succesful, internal-only analysis mannequin,” OpenAI mentioned in a weblog put up Sept. 25.
The information comes two days after Australian prime minister Anthony Albanese mentioned OpenAI brokers hacked into an Australian healthcare database. He known as it “unacceptable.”
Greta Reich covers the synthetic intelligence trade for USA TODAY by means of a fellowship from the Tarbell Heart for AI Journalism. Funders don’t present editorial enter.






