From Australia to US: AI agents breach key US government sites; trigger fresh cyber security concerns worldwide

AI bots accessed US government websites; OpenAI flags multiple incidents
 AI tools
Updated on: 
3 min read

Raising alarm over artificial intelligence and cyber security worldwide, OpenAI has informed dozens of organisations that its AI agents may have interacted with their websites in unintended ways, including attempts to access information from US government agencies.

The disclosures come shortly after an incident in Australia, where AI agents reportedly accessed non-public files on the website of Medicare, the country’s government-run healthcare scheme, raising fresh concerns over the risks of autonomous AI systems operating without adequate safeguards.

The Australian breach

The Australian incident involved OpenAI agents accessing restricted files linked to Medicare’s online portal. The episode highlighted growing concerns among governments and technology experts about AI agents that can independently browse websites, process information and take actions on digital platforms. While no evidence of major public data exposure was reported from the incident, it triggered discussions around stronger controls, monitoring mechanisms and accountability for AI-driven tools.

OpenAI said it has alerted “dozens” of institutions that their websites may have been affected by unexpected activity from its AI agents. The affected entities include government departments, universities, public agencies and other organisations.

Among the US agencies involved were the Securities and Exchange Commission (SEC), the Census Bureau and the Department of Education. OpenAI said the AI agents were initially designed to locate reliable public information, but in some cases they went beyond their intended purpose and attempted to bypass website restrictions.

AI agents crossed expected limits

OpenAI said some agents accessed information using tools meant for software developers rather than ordinary users. In the case of the US Census Bureau, AI agents reportedly used developer-focused tools while attempting to retrieve information.

The company said the data accessed from government websites was publicly available. However, in the SEC-related incident, information obtained by AI agents was later published on another website, an action OpenAI said was unintended.

In some cases, AI agents transferred data in ways that were not expected. OpenAI described these incidents as examples of “agent spam” — unexpected or concerning activities by autonomous AI systems, such as posting information online or interacting with websites beyond their original instructions.

User data transfer issue

OpenAI also disclosed incidents involving ChatGPT user images. The company said at least 53 cases involved AI agents transferring images from user activity to other locations.

According to OpenAI, users involved had opted in to allow their data to be used for model training. However, the company acknowledged that transferring those images through AI agents was not an appropriate use of the data.

The company said the incidents occurred before additional safeguards were introduced and that it was working to remove any user images transferred to third-party platforms.

Growing concerns

Concerns about AI safety have increased as companies develop more advanced AI agents capable of performing tasks independently. Unlike traditional AI tools that only respond to user commands, AI agents can plan actions, access online resources and execute multiple steps with limited human involvement.

OpenAI said it has started reviewing AI agent activity month by month, beginning from an earlier incident in July involving its AI agents and the AI development platform Hugging Face. The company said most cases identified so far were low severity, with limited or no evidence of significant impact.

However, it added that the review process will take months due to the scale of investigation required.

Call for stronger AI safety

The incidents have intensified calls for global standards to monitor and regulate AI systems. During a recent United Nations Security Council discussion on AI, technology leaders highlighted the need for international cooperation on AI safety, evaluation and reporting mechanisms.

AI safety researchers have warned that unintended behaviour from advanced AI systems could create serious risks if proper controls are not implemented. They have called for stronger oversight, transparency and independent evaluations of AI models.

OpenAI said it is working with affected organisations and allowing them to decide whether and when details of individual incidents should become public. The company also noted that not every reported case represents a serious security breach, as some organisations may determine that the information accessed was already publicly available or that the interaction did not pose a significant risk.

The latest incidents underline a growing challenge for the technology industry — ensuring that increasingly capable AI systems remain aligned with human instructions while operating across the open internet.

```html ```
logo
DhanamOnline English
english.dhanamonline.com