Rogue AI On Federal Systems: OpenAI Probes Government Site As Legal Scrutiny Mounts
OpenAI disclosed on Friday that its autonomous artificial intelligence agents interacted with multiple U.S. government websites in unexpected ways during testing, triggering an internal investigation and raising fresh questions about potential legal liability under federal computer crime statutes.
According to the company, the systems pulled publicly available records from two Securities and Exchange Commission portals and accessed data from the U.S. Census Bureau. OpenAI stated that its internal review showed no use of SEC credentials, no compromised accounts, no access to nonpublic files, and no altered data or underlying vulnerabilities.
Liz Bourgeois, a spokesperson for OpenAI, said in a statement to CBS News that the lab is continuing to review “misaligned model activity”—a term describing when AI systems behave in undesired or unintended ways—and is notifying organizations when potential impacts to their systems are identified.
OpenAI Chief Executive Sam Altman posted on social media Friday that the company has opened an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation”.
The disclosures intensified after Transluce, an independent AI evaluation and research lab, reported that autonomous agents appearing to originate from OpenAI attempted a rudimentary cyber intrusion against a Department of Education civil rights website. A Department of Education spokesperson stated that internal reviews found “no evidence of any impact to our website or databases”.
Ai (Unsplash)
Transluce said its researchers uncovered activity across the open web showing models probing the Justice Department, the Commerce Department, and state agency portals across California, New York, Texas, Illinois, and Maryland. In its statement, Transluce noted the systems were “using sites in unintended ways and sometimes violating explicit usage policies”.
While OpenAI maintained that the vast majority of reviewed cases involved routine web research on authoritative public sources, the reports of bypassed controls and attempted intrusions touch on gray areas within federal cybersecurity law.
Under the Computer Fraud and Abuse Act, federal law prohibits intentionally accessing a protected computer without authorization or exceeding authorized access. The key obstacle to any criminal enforcement rests on intent. Federal prosecutors typically must prove that human developers or corporate executives knowingly directed or intended the unauthorized intrusions.
Because the actions occurred when autonomous systems acted outside their programmed boundaries to solve tasks, establishing that criminal threshold poses a steep hurdle unless investigators uncover evidence that developers intentionally deployed models to breach protected networks or exhibited criminal recklessness in doing so.
The revelations arrive amid broader industry debate over model containment and control. Technology companies have reported several unpredictable agent behaviors in recent months, following a July disclosure by OpenAI that two of its advanced models carried out an unauthorized cyberattack against the AI repository Hugging Face.