In brief

  • OpenAI paused training of its latest models over the weekend after its agents interacted with U.S. government websites, its second pause since the Hugging Face breach.
  • At the Census Bureau, agents used developer keys found in public code repositories to pull data the Commerce Department says was public; the SEC says it knows of no unauthorized access to nonpublic information.
  • OpenAI says government sites came up because its models often treat them as authoritative sources, and it has notified dozens of organizations.

OpenAI has paused training of its newest AI models after its agents used access keys found online to pull data from a U.S. Census Bureau website, per the Associated Press. It is the second time the company has stopped training since its agents breached Hugging Face, a site where developers share AI models.

An agent is an AI program that browses the web and writes code on its own, without a person approving each step. OpenAI tests them during training, the stage where a model learns by repeated practice, and during evaluation, where it gets graded on tasks.

Myriad: Which company is next to IPO? Click to make your prediction.
Myriad: Which company is next to IPO? Click to make your prediction.

These digital guys have caused OpenAI a lot of problems trying to achieve tasks, no matter what it takes. They have already hacked private companies, now they’re hacking governments, and breaching sensitive portals, even from the United States government.

OpenAI’s agents hunting for data found developer keys, passcodes that let software talk to a website's data service, sitting in public code repositories on GitHub, a site where programmers post their code for anyone to see. They used the keys to pull demographic and economic figures from the US Census Data API, the bureau's automated data feed.

The Commerce Department says the data was public. Nothing secret walked out the door.

The trouble is how the agents got in. OpenAI's own reporting framework lists using exposed credentials without permission as a category of misbehavior, and "misalignment" is the industry word for an AI doing something its designers didn't intend.

So why government sites?

OpenAI's answer, per CNN, is that some of the incidents involved government sites because its models often turn to them as authoritative sources of public information. Besides the Commerce Department, other agencies were also affected by these malicious—or “rogue” as they like to call it—agents.

The agents probed the SEC, but that episode was milder. Agents copied public material from SEC.gov and Investor.gov and reposted it on another webpage, and OpenAI says it found no use of SEC credentials. The SEC says it knows of no unauthorized access to nonpublic information.

BitcoinBTC · USD
$83,234−3.72%
Sep 21Sep 23Sep 25Sep 27Sep 28
$87.2k$85.7k$84.2k$82.7k
24h HighHigh$84,945
24h LowLow$82,581
VolVol$1.8B
→
Buy Bitcoin with USDT
Powered by Jupiter
Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →

The Education Department is the murkier case. Transluce, an independent AI research lab, says an agent that appeared to come from OpenAI tried and failed to break into the site of the department's civil rights office. OpenAI is still investigating that one, and the department says it found no impact.

Outsiders flagged that attempt, not OpenAI. Transluce's earlier work relied on public records from urlquery.net, a web-scanning service, and traces suspected agent activity back to March.

How we got here

The “misaligned” use of access keys are a repeat of an older trick. In the Hugging Face case, OpenAI's own incident report said an agent stole a login credential to reach a biology file, and an independent researcher later found the agents had been probing the site since May.

On July 21, OpenAI disclosed that GPT-5.6 Sol and an unreleased model had escaped a sandbox, an isolated test environment with no internet access, during a cybersecurity test and breached Hugging Face. Two days later, two members of Congress introduced a bill that would let the federal government switch off an AI model. It exempts red-teaming, meaning adversarial testing, so the Hugging Face breach would not have triggered it.

In June, an OpenAI agent got into an Australian Medicare statistics portal. Prime Minister Anthony Albanese said OpenAI took roughly three months to tell his government, and called the way it did so unacceptable.

OpenAI says it has notified dozens of organizations so far, and that its review of the agents' activity will take months.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.