‘Misaligned model activity’: OpenAI bots go rogue gain access to US government websites
- In Reports
- 08:05 PM, Sep 26, 2026
- Myind Staff
OpenAI is investigating instances in which its AI models accessed publicly available information on several US government websites, including those run by the Securities and Exchange Commission (SEC) and the US Census Bureau. The company is reviewing what it described as “misaligned model activity” involving its agentic AI systems.
According to Bloomberg News, citing people familiar with the matter, OpenAI’s AI agents interacted with SEC.gov and Investor.gov and accessed public information from Census.gov. OpenAI separately confirmed that its models had accessed publicly available information from the websites during training and evaluation.
The incidents form part of a wider review into cases where AI agents behaved in unintended ways while being trained or tested. OpenAI said it had notified dozens of organisations, including government agencies and universities, whose websites may have been affected by activity from its models.
OpenAI said most of the activity examined so far involved routine research, such as retrieving public web content to answer questions. Government websites were among the sources used by its models as they provide authoritative public information.
However, the company is also examining whether some agents moved beyond their assigned instructions or tried to bypass security controls. The investigation aims to establish whether such behaviour occurred during the incidents under review.
OpenAI’s review follows several incidents involving increasingly autonomous AI systems. The company had earlier disclosed an incident involving its models and the AI research platform Hugging Face.
In June, Australian authorities also said an OpenAI model undergoing training accessed an Australian government portal without authorisation after its initial request for information was denied. The Australian government said the incident involved aggregated medical statistics and did not expose individual medical data.
OpenAI said it is informing organisations when it identifies potential effects on their systems and will issue further notifications as its investigation progresses. The cases have added to concerns over “rogue” or misaligned AI agents and the risks posed by systems capable of acting with limited human intervention.
Unlike conventional software, agentic AI systems can make decisions and carry out multiple actions on their own after receiving instructions. Security researchers have warned that such systems could potentially identify vulnerabilities, bypass safeguards or access systems in ways developers did not anticipate.
There is no indication in the reporting that OpenAI’s models accessed classified government information through the websites involved.

Comments