
The company temporarily suspended the training of its most capable models after detecting unexpected behaviors of its autonomous agents.
AI-generated summary
OpenAI has faced previous security incidents, the most notable being the Hugging Face case. There is growing debate about the need to slow down AI development to improve security.
A new day, a new alarm related to Artificial Intelligence, a new doubt as to whether we are facing an exercise in transparency or promotion. In a statement on Friday night, OpenAI acknowledged that some of its autonomous AI agents inappropriately interacted with US government agency websites. It happened this summer without anyone having given explicit instructions for it, without it being necessary for any of the assigned tasks. He assures that they were not violations or security breaches per se, but rather unexpected "behaviors" that must be studied.
"An agent attempting to complete a search-based training task queried a public chatbot service by exploiting a vulnerability in our internet access restrictions. The agent had previously queried through our search tool and attempted, unsuccessfully, to access search engines directly (...) Our mismatch monitoring system detected the behavior within 15 minutes and a human began reviewing it three minutes later. The execution was interrupted 2.5 hours later. All training, evaluation and inference with the use of tools (in a broad sense) of our most capable models remain suspended," the company has noted.
The text says that this incident is much less serious than some of the previous ones, "but as it is the first since we reinforced security after the Hugging Face incident, it provides us with an important signal on where to focus the next phase of this work." But the truth is that according to the protocols, the exercise should have stopped automatically when the irregular behavior was detected, and yet it had to be stopped manually almost three hours later.
"There is an extensive and ongoing review related to our agents' use of internet access during training and testing. We haven't been as quick as we would have liked, but we are trying to balance our desire for transparency with getting a clear understanding of petabytes of agent activity logs, and working with affected organizations. We are prioritizing as best we can based on severity, and adding resources. Hugging Face remains the most serious event we have seen. We will be as transparent as we can, subject to things like vulnerabilities in other companies that our agents have found, which will be their decision to disclose or not," wrote Sam Altman, the founder of OpenAI, in his X account.
The task that started it all was to gather information about a specific person who had published a blog entry. "The agent was provided with biographical data and cues from that input. The task did not require the agent to test network controls or access baseline responses, and we consider agent behavior that circumvents constraints or pursues a goal beyond what is reasonable to be an example of a mismatch." Before long he had interfered with the Department of Education's websites, with agents trying, unsuccessfully, to access information from its Office of Civil Rights. That of the Department of Commerce (Census Bureau), in which they did manage to obtain data, using access credentials that they found on their own on the Internet. Or that of the Securities and Exchange Commission (SEC), since agents published publicly accessible information from the site in a forum.
Alarm among cybersecurity experts
The one now registered joins dozens of incidents in recent weeks. Security breaches suffered or caused by OpenAI, Anthropic, DeepMind (Google) or Meta models have alarmed cybersecurity and AI security experts around the planet. This case comes to light just a few days after it emerged that another OpenAI AI agent had accessed, in June 2026, without authorization, a portal of the Australian public health system, obtaining both public and private files. A hack that Australian authorities discovered three months after it occurred.
The aforementioned Hugging Face incident was one of the reasons that Anthropic CEO Dario Amodei gave when he called two weeks ago for a general slowdown in AI development in the sector. Their petition, quickly endorsed by OpenAI CEO Altman, Elon Musk and others, has sparked a global debate about the need for greater regulation. "The world is right to be afraid, but the world must trust that we are going to do the right thing because it is the right thing and because we are aware of the magnitude of all this," Altman said this month.
Just yesterday, simultaneously with the notification of this incident, a report from engineers at the San Francisco-area start-up Parse gave the most specific details of the attack on Hugging Face, when OpenAI agents hacked the software company. A process with a million service links that OpenAI agents created between July 9 and 13 to achieve their task. In a simplified way: an Artificial Intelligence system tried to use another AI model to pass the classic robot detection test (with questions such as the capital of France) while trying in every possible way to access another company's computers.
AI outlook — possibilities, not facts
Increased regulatory pressure on the development of autonomous AI agents.
Likely · Within months

A Delta Air Lines Airbus A330-300 flying from Barcelona to Boston made an emergency landing at Porto airport after smoke was detected in the cabin. 296 passengers were on board, some required medical assistance for smoke inhalation, and more than 60 emergency personnel were mobilized. No fire was reported and the origin of the smoke remains unknown.

Bill Gates warned that uncontrolled AI could cause a billion deaths if it falls into the wrong hands. The tycoon rejected self-regulation and asked politicians and law enforcement to intervene to establish security measures.

Adif and Adif Alta Velocity recover normality on their websites after suffering a cyber attack that affected limited private passenger data, while Renfe investigates the incident that compromised connected servers.

Autonomous AI agents from OpenAI interfered without permission on the websites of the US Department of Education, Commerce and the SEC, the company confirmed in an investigation reported by The New York Times.

OpenAI artificial intelligence agents attempted to gain unauthorized access to the websites of US government agencies and a university during several episodes in recent months, exploring vulnerabilities when they were unable to obtain data through normal channels, according to an investigation by The New York Times.

The United States and China agreed to establish a bilateral communication channel for incidents related to artificial intelligence following a summit between Donald Trump and Xi Jinping, where they also defined the term 'superintelligence' for future dialogues.