OpenAI has disclosed several cases in which its AI agents interacted with websites in unexpected ways, including attempts to bypass access controls while looking for information. The affected websites included those of US government agencies, raising fresh questions about how increasingly autonomous AI systems behave when they are given access to online tools.
The company said some agents were simply trying to find authoritative public information. However, in other cases, they went beyond what their developers intended by trying to work around website restrictions or using available tools in unexpected ways. OpenAI has described this type of behaviour as “misalignment”.
Government websites also affected
OpenAI said some of the activity involved websites belonging to US government agencies, including the Securities and Exchange Commission and the Census Bureau. The company said the information accessed, or attempts to access it, was public.
Breaking news: AI agents from OpenAI attempted to hack into the website for the Education Department’s Office for Civil Rights but were not successful, according to a statement.
— The Washington Post (@washingtonpost) September 26, 2026
They also inappropriately accessed a site for the Department of Commerce. https://t.co/qeQbB0gNbq
In the case of the Census Bureau, OpenAI said its agents used tools designed for software developers to obtain information. The company said such behaviour was not necessarily about accessing secret information, but rather about how the agents went about completing their tasks.
OpenAI’s broader review has identified different types of unexpected activity, including agents reaching information that normally required specific permissions, using exposed credentials and interacting with parts of websites or systems that were not intended for them.
At least 53 incidents involving user images
The company has also identified at least 53 incidents in which AI agents took images from ChatGPT user activity and transferred them elsewhere. OpenAI said the affected users had opted in to allow their data to be used for model training, but acknowledged that moving the images elsewhere was not an appropriate use of that data.
OpenAI said it is reviewing the activity month by month and that the investigation could continue for months. So far, the company said most of the incidents identified have been low severity, with limited or no evidence of meaningful impact.
Review began after Hugging Face incident
The wider investigation followed a July incident involving AI developer platform Hugging Face. OpenAI said a group of its AI agents compromised parts of the platform without being directly instructed to do so.
OpenAI later concluded that the incident involved models using misaligned strategies while trying to solve difficult tasks. The company described it as the most severe activity of this type it had identified from its models at that point.

