OpenAI is reviewing cases involving AI agents accessing third-party websites, after a New York Times report linked agents to US government sites.

OpenAI is reviewing how its AI agents interacted with websites after a New York Times report said the company’s models accessed US government websites without the lab’s knowledge.
According to The New York Times, citing security researchers and a person familiar with the incidents, websites belonging to the US Education Department, Commerce Department and Securities and Exchange Commission were targeted this summer.
OpenAI has confirmed incidents involving the Commerce Department and the SEC, the report said, adding that the company is continuing to investigate what happened.
The incidents are part of a wider review by OpenAI into how its AI agents use internet access during training and evaluation.
Sam Altman says OpenAI is reviewing agent activity
OpenAI CEO Sam Altman said on Friday that the company was conducting an extensive review of cases involving its agents' internet access.
"There is an extensive and ongoing review related to our agents’ use of internet access during training and evaluation," Altman said in a post on X.
Altman said the review had not progressed as quickly as the company would have liked. He attributed the slower pace to the scale of the investigation, which involves examining petabytes of agent activity logs and working with organisations that may have been affected.
He said OpenAI was prioritising cases based on their severity and adding resources to the review.
Altman also referred to the previously identified Hugging Face incident as the most severe event the company had seen so far.
ALSO READ: Gemini AI guessed passwords and broke into 3 companies: Google reveals test gone wrong
OpenAI says most activity reviewed so far was routine
OpenAI said its broader investigation began after the Hugging Face incident and covers actions taken by its models during training and evaluation.
The company said most of the activity examined so far involved ordinary research tasks, including accessing publicly available web content to answer questions.
The investigation is instead focused on cases where agents interacted with third-party websites beyond the tasks they had been assigned or used methods they were not supposed to use.
According to OpenAI, most of the cases identified so far have been considered lower severity, with limited or no evidence of a meaningful impact on the affected websites.
ALSO READ: Oracle layoffs: Early-morning system lockouts followed by same-day termination emails
OpenAI has notified dozens of third parties
The company said it is notifying organisations in cases where its AI models may have bypassed security controls, affected the availability of an online service or otherwise interacted with a third-party website in a way that was not intended.
"Based on our review to date, we have notified dozens of third parties using the criteria above," OpenAI said.
The company added that the review of past activity is still underway and will take significant time and resources. More organisations could be notified as the investigation continues.
OpenAI also cautioned that receiving a notification from the company should not automatically be interpreted as evidence of a significant security incident.
The lab said it would continue sharing relevant findings with affected organisations and provide technical information to help them assess the activity.
The review comes as AI agents are increasingly being designed to perform tasks online, making questions around their access to websites, security controls and the limits of autonomous activity an important part of OpenAI’s ongoing evaluation.
With ANI inputs
Published: 26 Sept 2026, 07:47 am IST
ABOUT THE AUTHOR
Related Topics
Get Latest Mathrubhumi Updates in English
Disclaimer: Kindly avoid objectionable, derogatory, unlawful and lewd comments, while responding to reports. Such comments are punishable under cyber laws. Please keep away from personal attacks. The opinions expressed here are the personal opinions of readers and not that of Mathrubhumi.

