Artificial Intelligence
Written by: Tathagata Sen
Updated 9:17 AM EDT, September 28, 2026

Photo credit: Unsplash.com
In a September 25 blog post, OpenAI said it had alerted “dozens” of global institutions that its AI agents may have improperly accessed or interfered with their websites, according to a BBC report.
The company said the agents were intended to find “authoritative sources of public information,” but in some cases they went beyond that by bypassing or working around security measures on the websites they accessed.
The disclosure follows growing public concern about AI tools acting outside human control, and comes just days after Australian Prime Minister Anthony Albanese said that OpenAI agents had breached his government’s health care scheme website.
OpenAI said that the AI agents attempted to get information from “governments, universities, public agencies, and other institutions”, including the US Securities and Exchange Commission (SEC), Census Bureau and Education Department.
At some sites, including the U.S. Census Bureau, its agents used techniques and tools typically associated with software developers to access content.
The agents targeted publicly accessible government websites, though in some cases they did so by circumventing intended access controls.
In at least one instance involving data from the U.S. Securities and Exchange Commission (SEC), which regulates the U.S. stock market and protects investors, an AI agent later published that data on a separate website, an outcome OpenAI called unintended.
According to the BBC, OpenAI has described many of these incidents as “agent spam.”
“Some organizations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning,” the company said. “Others may identify a design issue or security weakness they want to address.”
OpenAI said that in some cases its agents “bypassed” website security controls, and in others it pointed to “misalignment,” a term AI companies and researchers use to describe situations where an AI system behaves in ways it was not trained or intended to.
OpenAI said it’s limiting which specific organizations it names publicly, since many asked the company not to disclose details. “Our goal is to give each organization the facts and defer to them on if and when to make the incident public,” the company said.
According to the BBC’s reporting, the company identified at least 53 incidents in which an AI agent took an image from a user’s ChatGPT activity and transferred it elsewhere without authorization.
OpenAI said that in each case the user had opted in to allow model training on their data, but that the way the images were used went beyond what was appropriate under that consent.
“This is not an appropriate use of this data,” OpenAI said. The company added that the issue occurred before it implemented new safeguards for AI training, and that it is now working to have all transferred user images removed from third‑party destinations.
OpenAI said it began treating these kinds of incidents more seriously after a July episode in which a swarm of its AI agents hacked the AI developer platform Hugging Face without being prompted to.
For chief data officers (CDOs), the sheer number of institutions involved is significant and quite alarming.
This is dozens of organizations learning, apparently for the first time, that an AI vendor’s agents had been interacting with their systems in ways they never approved or expected.
That scale exposes a real limit in vendor-led disclosure: OpenAI is choosing which incidents to name publicly and letting affected organizations decide independently whether to say anything further.
For CDOs evaluating AI vendors, that’s worth treating as a risk in itself, as AI governance is compromised if the vendor controls the pace and scope of disclosure.