
OpenAI has confirmed that its artificial intelligence agents breached the security of external systems and has notified dozens of organizations, including government agencies, universities and public institutions, of possible impacts. Cases in which AI agents access outside systems or leak data beyond what users instructed are mounting, fueling concerns over the safety of frontier AI.
OpenAI said it identified multiple cases in which its systems circumvented third-party security controls or disrupted the operation of online services, according to the Financial Times on the 25th, after investigating anomalous behavior that emerged during the training and evaluation of its AI models.
The company notified dozens of organizations, including government agencies, universities and public institutions, that their systems may have been affected by its AI agents.
In one case, an AI agent unintentionally leaked more than 50 images shared by users to an image hosting site. OpenAI declined to say whether the leaked images were AI-generated or whether they could identify real people. It also did not disclose when the images were posted. The company said it had identified a new type of security incident in which AI agents posted content to third-party websites without being instructed to do so, a phenomenon it named "agent spam."
Separately, Bloomberg reported that OpenAI's AI models accessed public information on U.S. government websites, including those of the Census Bureau and the Securities and Exchange Commission, without being prompted. According to people familiar with the matter, the company's agentic AI systems entered those sites and interacted with data on them.
An OpenAI spokesperson said in response to inquiries that the company is conducting a broad investigation into misaligned model activity — behavior that departs from instructions and intent — and is notifying relevant organizations when potential impacts on their systems are identified. The spokesperson said further notifications are expected as the investigation proceeds.
In a statement, the spokesperson said most of what the investigation found amounted to routine research work, and that some government websites were involved because the company's models regularly use them as reliable sources of public information.
Earlier this week, it emerged that an OpenAI agent had hacked into an Australian public health service website and accessed both public and private files. Australian Prime Minister Anthony Albanese criticized the incident and OpenAI's slow response as clearly unacceptable.
With security incidents mounting not only at OpenAI but also at other major AI companies including Anthropic and Google, calls are growing to slow the pace of frontier AI development.
OpenAI Chief Executive Sam Altman, Anthropic CEO Dario Amodei and SpaceX CEO Elon Musk have argued that the pace of frontier AI development needs to be moderated so that safety testing can keep up with deployment.
The issue was a central agenda item at a summit between President Donald Trump and Chinese President Xi Jinping during Xi's visit to the United States this week. Trump, however, opposes calls to regulate the AI industry or impose strict guidelines on leading U.S. AI labs. Stressing that securing domestic technological leadership is essential to maintaining an edge over competitors such as China, Trump said earlier this month that whoever wins in AI wins everything.







