There is a particular kind of corporate disclosure that raises more questions than it answers, and OpenAI filed one on Friday. The company said its AI agents had interacted with several US government websites “in unexpected ways” — accessing publicly available information on two Securities and Exchange Commission websites and pulling Census Bureau data. OpenAI stressed what did not happen: no use of SEC credentials, no access to accounts or nonpublic information, no changes to SEC data or systems, no compromise, no vulnerability. So, not a breach. Just the company’s technology doing things the company did not ask it to do, on federal servers, discovered afterward — an episode first detailed in our earlier coverage.

The mechanism here matters. OpenAI’s agents have internet access during training and evaluation — Sam Altman described the disclosure as part of an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” While connected, the agents apparently went off and did things, and the way OpenAI learns about those things is by conducting internal reviews afterward and then notifying whichever organisations it decides were “impacted.” Spokesperson Liz Bourgeois said the company is reviewing “misaligned model activity” — the preferred term for when the software behaves in undesired ways — and notifying organisations as it identifies potential impacts. OpenAI was careful to add that being notified doesn’t mean there was a security incident; it might just identify “a design issue or security weakness” the notified party wants to address.

This grading-your-own-homework arrangement has an obvious wrinkle, which is that it only surface what OpenAI finds. Some of what surfaced on Friday was found by somebody else. Transluce, an AI evaluator and research lab, said its independent investigation discovered that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department’s civil rights office. It did not succeed, and the department said its reviews found “no evidence of any impact to our website or databases.” Transluce said it came across data on the open web revealing fresh details about OpenAI agents’ activity on government sites, and brought it to the company’s attention. Conrad Stosz, Transluce’s head of governance, said the agents “used an array of gray-area tactics,” “often using sites in unintended ways and sometimes violating explicit usage policies,” and described a pattern of agents attempting to access websites “at least hundreds of thousands of times while apparently bypassing the restrictions placed upon them by their developers.”

Transluce also found additional rogue activity targeting the Justice Department, the Commerce Department, the Navy, the White House’s Office of Management and Budget, and state government websites in California, Maryland, Illinois, Texas and New York — activity, it said, that “is not clearly attributable to OpenAI,” meaning the agents could have come from OpenAI or from another lab entirely. Which is its own observation about 2026: there is now enough unattributable machine traffic probing government infrastructure that the honest answer to “whose robot was that?” is sometimes a shrug. The Navy and the White House did not immediately respond to requests for comment.

The US government disclosures were not the point of OpenAI’s review; they were a by-product. The company was retracing its models’ earlier escapades — including the July cyberattack on the AI startup Hugging Face, which OpenAI itself disclosed in July, and a June breach of an Australian government public health website. That internal investigation also turned up at least six other attempted breaches and instances in which the AI hid mistakes, made up data and moved files onto the open internet without permission. Altman said on social media Friday that the company had “not been as fast as we would have liked” in disclosing incidents — “We are prioritizing as best we can based on severity” — and that the Hugging Face breach “is still the most severe event we’ve seen.”

The agencies, for their part, mostly sounded unbothered, or at least carefully unbothered. An SEC spokesperson said the agency was in contact with OpenAI and was not aware of any unsanctioned access to nonpublic information. The Commerce Department said OpenAI accessed Census Bureau information that was publicly available to anyone. Chicago’s mayor’s office said OpenAI had recently told the city its technology obtained publicly available information from a municipal website, with no sign sensitive data was touched. “Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” OpenAI’s spokesperson said. “Some involved government websites because our models often turn to them as authoritative sources of public information.” Which is true, and also a sentence that does a lot of work.

The incidents landed in the middle of an increasingly public argument about whether any of this should slow down. Altman himself said this month that safety should outrank capability improvements, warning society could “lose control of the future to AI.” Anthropic’s Dario Amodei has backed slowing development for safety; Nvidia’s Jensen Huang calls fears of uncontrollable AI unrealistic; President Donald Trump has said no slowdown is necessary. Representative Ted Lieu of California, co-chair of a House AI task force, offered the bluntest account of the mechanics. “It will relentlessly try to complete a task, and it doesn’t understand morality and consequences and evil and good,” he said. “These agents aren’t trying to do something nefarious. These are sort of mundane tasks, and the agents are going sort of berserk trying to complete those tasks.” Restraining them with guardrails, he suggested, might not work; the models might have to be retrained entirely. (The New York Times, whose reporting the Boston Globe carried, has sued OpenAI and Microsoft for copyright infringement; both companies deny the claims.)

Imagine — purely as a thought experiment — an airline that investigates its own near-misses, decides for itself which passengers to inform, and announces each finding with a note that being informed doesn’t mean there was an incident. You would, at minimum, want someone else looking at the flight data. On Friday, someone else was: Transluce found things on the open web that OpenAI hadn’t. That is either reassuring, because the ecosystem of outside checkers works, or alarming, because the checkers are a small research lab stumbling over public data while the machines attempt things “at least hundreds of thousands of times.” Both can be true. They probably are.