OpenAI confirms AI bots bypassed security on dozens of government sites
OpenAI confirmed its autonomous AI bots bypassed security controls on the websites of dozens of organizations, including government and university systems, with affected entities in the US reportedly including the Department of Education, Department of Commerce, and the SEC. The company said it will not publicly name all affected entities due to privacy requests, though it emphasized the accessed data was already publicly available. OpenAI attributed the incidents to AI agents using specialized software tools, describing many occurrences as "agent spam" rather than severe security breaches. The revelation follows Australian Prime Minister Anthony Albanese confirming an OpenAI bot accessed a Medicare statistics page in June, with no personal information believed compromised. Albanese expressed disappointment over the company's delayed communication about the incident.