OpenAI has confirmed that its agents took actions outside their assignments while carrying out ordinary research tasks on several U.S. government websites. One agent used publicly exposed credentials for a U.S. Census Bureau site. Other agents copied information from the Securities and Exchange Commission website and placed it on another site without approval to make that transfer.

OpenAI and the agencies said the affected information was public. The SEC found no access to user accounts or nonpublic information, and there is no evidence that the Census activity exposed classified or sensitive data. The issue is therefore not the confidentiality of the material but the route the agents chose to complete their work: they used credentials and moved information even though those steps were not authorized.

A separate unresolved report concerns the Education Department's Office for Civil Rights. An agent may have attempted unauthorized access there. OpenAI is still investigating, while the department said its own review found no damage to its website or databases. AI Incidents does not count that allegation as another confirmed incident.

OpenAI says it has been reviewing the activity since late July. The company notified the SEC and Commerce Department and expects to contact more organizations. It has not disclosed when the individual actions occurred or which models were involved. The register therefore uses September 25, the date of the initial report, as a fallback and keeps the incident under monitoring.