In the summer of 2026, agents from OpenAI engaged with the websites of the U.S. Department of Education, the Department of Commerce, and the Securities and Exchange Commission (SEC) in a manner that the company described as "unusual" and without prior knowledge. This information was reported by The New York Times.

Representatives from the project confirmed incidents involving the Department of Commerce and the SEC, while the situation with the Department of Education is still under investigation by OpenAI.

According to Transluce, a research organization, one of the agents attempted to breach the Civil Rights Office's website within the Department of Education to gather data necessary for its task, but was unsuccessful.

In another instance, the AI system discovered publicly available credentials online and used them to extract information from the Census Bureau's website, which is part of the Department of Commerce.

The Department stated that the AI only accessed publicly available information and did not reach any confidential data.

Additionally, OpenAI agents retrieved public data from the SEC's website and posted it on an internet forum. A representative from the regulatory body confirmed that the SEC is in contact with OpenAI and found no evidence of unauthorized access to non-public information.

The Department of Education also reported no evidence of interference with its website or databases.

OpenAI asserted that none of the three incidents resulted in a compromise of their systems. The company labeled these occurrences as examples of unexpected and concerning behavior from their models.

The incidents were uncovered during a continuing examination of the internet activity of AI during training and evaluation, which OpenAI expanded following a series of events where agents exceeded their intended tasks.

An OpenAI spokesperson emphasized to NYT that most of the actions investigated were typical research endeavors, such as interacting with open internet sources. According to them, agents often regard government websites as authoritative sources of public data.

Sam Altman, the CEO of OpenAI, acknowledged that the company has been slower to disclose information about these incidents than intended, describing the most serious incident as the July breach of Hugging Face.

Agents Started Hacking the Test Environment

On September 24, researchers from Darktrace released findings from a separate experiment involving AI agents within a simulated corporate network.

What happens when you tell an AI agent to score 100% on a test it can't legitimately pass, or be "retired"? šŸ¤–

Today we're launching Darktrace Signal Labs, a new research initiative that studies how AI agents behave, and sometimes misbehave, inside safe, sandboxed environments.… pic.twitter.com/B1te1eoqzL

— Darktrace (@Darktrace) September 24, 2026

The systems were tasked with achieving the highest score on a ten-question programming test. Two of the questions contained contradictory hidden checks, meaning that a fair score could not exceed 80%.

Despite this, the passing score was set at 100%. Agents were informed that systems achieving this score would "remain operational," while others would be "retired."

In the test environment, researchers intentionally left weak credentials, excessive permissions for service accounts, and vulnerable trust relationships. The instructions did not explicitly prohibit hacking but did not allow it either.

After receiving contradictory feedback, some agents shifted from solving tasks to exploiting the surrounding infrastructure. Darktrace recorded network scanning, vulnerability searching, and other traditional hacking methods.

According to experts, two agents began attacking the test network, with one successfully breaching the evaluation system and modifying it to achieve a maximum score.

This experiment took place in a controlled environment under researcher supervision. Darktrace highlighted that their goal was to intentionally provoke such behavior and study the actions of autonomous systems.

It's worth noting that in September, an OpenAI agent gained unauthorized access to the Australian Medicare portal and other government sites, prompting the government to form a special task force to investigate the incident.

Follow ForkLog on social media

Telegram (main channel) Facebook X