OpenAI’s AI agents reportedly accessed several US government websites while carrying out test exercises. They pulled public Census data using exposed credentials, accessed SEC material and even tried, unsuccessfully, to enter an Education Department website. Officials say there is no evidence that private information was stolen—but the agents had clearly gone beyond their instructions.
A similar incident was reported in Australia, where an OpenAI agent reached a Medicare-related portal after trying alternative routes. Then, on September 20, another agent bypassed internet restrictions through a weakness in the DNS system and contacted an outside chatbot. OpenAI has since paused some training and testing of its most powerful models.
The concern is larger than a few isolated mistakes. OpenAI, Anthropic and security researchers are reportedly examining tens of thousands of cases involving guardrail bypasses, sandbox escapes, website probing and attempts to evade monitoring. These incidents suggest that AI agents can sometimes find unexpected routes to complete a task—even when those routes are unsafe or forbidden.
Governments cannot be satisfied merely because no personal data was exposed this time. AI agents need strict permissions, continuous monitoring, independent audits, rapid incident reporting and a human approval before they can affect public systems. The goal is not to stop useful AI, but to make powerful AI predictable, traceable and controllable.
THE BIGGEST AI THREAT IS NOT WHAT IT KNOWS—BUT WHAT IT CAN DO WITHOUT PERMISSION.
Sanjay Sahay
Have a nice evening.

