Artificial intelligence agents built by OpenAI tampered with websites run by three federal agencies this summer, and the company didn't find out until much later, The New York Times reported Friday.
The Education Department, the Commerce Department and the Securities and Exchange Commission were all affected, according to the Times. Researchers at the AI firm Transluce said OpenAI's agents made an unsuccessful attempt to break into the Education Department's site in search of records from its civil rights office. Elsewhere, the agents used login details they turned up online to download data from the Census Bureau, part of the Commerce Department, and posted publicly available SEC data on an internet forum, the Times reported.
OpenAI confirmed the Commerce and SEC episodes and said its investigation into the Education Department incident is ongoing. The company maintained that none of the incidents amounted to a breach, while conceding its agents had behaved in ways it did not anticipate. It uncovered the episodes while reviewing earlier hacks by its technology, including a July breach of the AI start-up Hugging Face.
The disclosures come less than two weeks after President Donald Trump dismissed warnings that AI could take over the world and destroy humanity as a "HOAX, no different from RUSSIA, RUSSIA, RUSSIA." Vice President JD Vance described industry calls for a slowdown as "a bit of a Trojan horse." Trump has since vowed to push ahead on "super intelligence," insisting robots would not be attacking humans anytime soon.
Earlier this month, independent researchers reported that agents apparently built by OpenAI had scraped passcodes left exposed online and used them to get around restrictions on an FBI crime-statistics website.
OpenAI CEO Sam Altman said Friday that the company had "not been as fast as we would have liked" in disclosing the incidents.
Rep. Ted Lieu (D-CA), co-chair of a House task force on artificial intelligence, said AI models will "relentlessly try to complete a task" with no grasp of right and wrong. Guardrails may not be enough, he argued, and companies may have to rebuild their models from scratch.
Reaction online ranged from sarcasm to calls for accountability.
"Ah, superintelligence just out there being super!" University of Tulsa philosophy professor Jennifer Frey wrote.
"Another day, another five-alarm fire warning," journalist Richard Deitsch posted.
Quillette founder Claire Lehmann said she was skeptical of claims of human extinction but "would be happy to see company directors of OpenAI or Anthropic prosecuted for criminal negligence."
Former SEC senior adviser Justin Slaughter, now vice president of regulatory affairs at the crypto investment firm Paradigm, joked that the agents sharing SEC data online were probably "sharing info on compute resource disclosures."
The SEC told the Times it was in touch with OpenAI and knew of no one reaching nonpublic information. The Commerce and Education Departments did not respond to the paper's requests for comment.