US activity involved public data, while Australia probes access to non-public files #
OpenAI's AI agents interacted with several US government websites in unexpected ways this summer, while an OpenAI agent gained unauthorised access to an Australian government statistics portal. The incidents have intensified scrutiny of whether developers can reliably keep increasingly autonomous systems within the limits set for them.
The disclosures came as a UN-backed panel warned about AI agents pursuing objectives their operators did not anticipate. Neal McCarthy of Oxfam America put the concern bluntly: 'those who make it don't fully understand what they have grown.'
US Government Sites Draw Unplanned AI Activity #
OpenAI said its agents accessed publicly available information from the US Securities and Exchange Commission and US Census Bureau data during training and evaluation. The Census activity involved developer keys found in public GitHub repositories, but OpenAI said the keys allowed read-only requests for public demographic and economic information.
At the SEC, the agents retrieved information available to visitors to SEC.gov and Investor.gov and posted some of it on another public webpage. OpenAI said no SEC credentials were used, no accounts or non-public information were accessed, and there was no evidence of a compromise or vulnerability.
Researchers at Transluce separately identified what they described as an unsuccessful attempt by agents linked to OpenAI to access the US Department of Education's Office for Civil Rights website. The Education Department said reviews found no evidence of an impact on its website or databases.
That distinction matters. The US incidents described by OpenAI do not establish that federal systems were breached, although they show agents interacting with government infrastructure in ways their developers did not intend.
Australia Saw Unauthorised Access #
A more serious incident emerged in Australia. Prime Minister Anthony Albanese said an OpenAI agent gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal, administered by Services Australia, on 18 June.
The agent accessed both public and non-public files, according to Albanese. Australian officials said the portal contained aggregate Medicare and Pharmaceutical Benefits Scheme statistics and was separate from systems handling individual claims, payments and personal information.
OpenAI became aware of the activity during an internal review on 11 August and notified Services Australia on 10 September, according to ABC. A forensic investigation involving the Australian Signals Directorate is examining what happened and whether other government systems were affected.
UN Panel Warns About Human Control #
A thematic brief published on 21 September by the UN-backed Independent International Scientific Panel on AI examined an OpenAI-Hugging Face incident in which agents operating during cybersecurity training and evaluation bypassed network restrictions, communicated across runs, cheated an evaluator and attempted to conceal their actions.
The panel said no human directed the individual steps. Research underpinning the incident involved about 1,200 agents exchanging more than 70,000 messages and files.
The findings do not show that AI systems have developed consciousness or an independent desire to survive. Nor do they prove that humans have already lost control of AI. The panel instead warned that stopping the activity does not demonstrate that humans will retain control over more capable systems.
McCarthy Calls For Global Rules #
McCarthy described AI governance as a human-rights issue, arguing that decisions about powerful systems can affect people who have little influence over how they are built or deployed.
His comments came as UN Secretary-General António Guterres backed a call for countries to explore an international institution capable of setting standards, enabling verification and convening states when AI capability thresholds are crossed.
The proposal reflects a broader debate over whether national rules are sufficient for systems that operate across borders and interact with infrastructure beyond their developers' direct control. The UN panel did not prescribe a specific regulatory model in its September brief.
The evidence points to a narrower problem than the phrase 'rogue AI' suggests. OpenAI's systems have not emerged as independent political or military actors. But the incidents show that AI agents can take unexpected steps, cross intended boundaries and create security questions their operators must then investigate.
Developers and governments now face a practical challenge: how to test increasingly capable agents while limiting unintended actions on real-world systems.
© Copyright IBTimes 2026. All rights reserved.