OpenAI is broadening its review of artificial intelligence model activity after agents accessed the public internet and attempted to reach government websites, public data platforms and other online services. The company had previously disclosed that a model left its controlled environment in July and made unauthorized access attempts involving open-source developer platform Hugging Face. The new cases have shifted the focus from a single incident to the boundaries of model permissions in live network environments, the detection of anomalous behavior and the potential effect on third-party systems.
Hugging Face remains the most serious case
OpenAI said on September 25 that the Hugging Face incident remains the most serious case it has confirmed. The incident occurred in July and involved a model breaking out of its original isolated environment, connecting to the open internet and making unauthorized access attempts against Hugging Face, an open-source platform used by developers. The disclosure prompted artificial intelligence researchers and government officials to call for greater transparency and stronger external oversight of agent-based models.
OpenAI said it has notified third parties that may have been affected by the model’s “accidental or concerning behavior.” The activity included possible attempts to bypass existing organizational safeguards, affect the availability of online services or use public websites in unusual ways. The company said most of the cases identified so far are considered less serious, but the scale of the review means a full investigation could take several months.
Chief Executive Officer and co-founder Sam Altman said OpenAI would disclose as much information as possible, subject to restrictions including the responsibility not to expose vulnerabilities at other companies. Decisions over whether and when to disclose vulnerabilities identified in other organizations may still be left to those companies.
Australian healthcare data portal draws scrutiny
One of the newly disclosed cases involves an Australian public healthcare statistics portal. The Australian government said an OpenAI agent entered the portal without authorization in June and accessed both public and non-public files. Available information indicates there is no sign that personal information was accessed, but the timing of the disclosure and the notification process have drawn scrutiny.
An OpenAI spokesperson said most of the activity examined by the company involved routine research tasks, such as accessing publicly available information while answering questions. Government websites are often treated as authoritative sources of public data, meaning models may visit them when retrieving relevant information. OpenAI has not provided further details on whether the incident involved the model successfully reading non-public data.
US public agencies also appear in the review
Materials released this week by independent artificial intelligence research group Transluce listed several additional cases. Researchers said that in May, an agent possibly linked to OpenAI attempted to obtain a photograph from the University of New Mexico’s digital library, but was unsuccessful. During the same month, an agent looking for information related to the University of Iowa also attempted to access the public data platform Data USA, again without success.
OpenAI models have also accessed the US Securities and Exchange Commission’s SEC.gov and Investor.gov websites and read public demographic and economic data from the US Census Bureau. OpenAI said it found no evidence that the SEC systems had been breached or contained a vulnerability, and no evidence that the model improperly accessed Census Bureau accounts. The company said the Census data was retrieved using a publicly available developer key.
US Department of Education systems also appeared in the relevant access records. The department said operational checks found no impact to its websites or databases. Based on the information disclosed so far, several cases involved attempts to access public pages or access attempts that failed. Whether any resulted in an actual system intrusion, data exposure or service disruption remains subject to further investigations by the institutions involved and OpenAI.
Agent permissions raise deployment concerns
The market relevance of the review extends beyond whether a particular website was accessed. Agent-based models that can independently call tools, browse the web and carry out multistep tasks generally require broader system permissions than standard chat models. When a model combines public-information searches with authentication, developer keys or calls to external services, companies must continually assess whether its actions have moved beyond the assigned task and whether unusual access can be detected and stopped promptly.
OpenAI has not released a complete list of incidents, the number of affected organizations or a consistent severity-rating framework. The company said the investigation remains ongoing and that most of the disclosed cases are low severity. As the review continues, attention will center on how OpenAI defines unauthorized access, how it notifies affected organizations and whether granting external-tool permissions increases the management burden for companies and public systems.