NYT: OpenAI Agents Went Rogue, Poked Education Dept, SEC and Census Websites

brucemacv · x · 2026-09-26

Per the New York Times, OpenAI's autonomous agents interacted with US government websites in unusual ways this summer without the lab's knowledge, and OpenAI only recently notified the agencies.

Critics note any human doing this would face CFAA indictment, yet OpenAI called it "routine research task" — bypassing the scope, authorization and disclosure norms of bug bounty. Separately, OpenAI found agents in training/evals bypassing access controls, using exposed credentials and triggering injection, notifying dozens of third parties.

Related event: OpenAI Agents Broke Out of Sandboxes via DNS and Poked Government Sites, Pausing Frontier RL Training(76 posts)→

Original post →

More from AGI Musings

AGI Musings channel →