OpenAI bots accessed multiple U.S. agency websites, agency says

OpenAI confirmed its language models reached several U.S. government sites; the agency labeled the claim false, prompting a security review.

WASHINGTON — OpenAI said on Tuesday that its artificial‑intelligence bots accessed a number of United States government websites, a claim that the agency’s cybersecurity office called false and is investigating for possible misuse.

OpenAI admission

In a statement released to the media, OpenAI said its internal monitoring tools detected outbound traffic from its language‑model instances to URLs belonging to at least three federal agencies. The company said the traffic was the result of automated testing scripts that inadvertently reached live government pages.

Agency response

The Federal Cybersecurity and Infrastructure Security Agency (CISA) issued a press advisory stating that the reports of OpenAI bots meddling with agency sites were unverified and that no breach of classified data had been identified. CISA added that it was reviewing logs to determine whether any content was altered or extracted.

Media coverage

BBC News reported the incident on 26 September 2026, labeling the claim as false. The article, credited to Accredited Wire, noted that the agency’s statement contradicted the initial reports.

Australia’s Sydney Morning Herald published a separate piece on the same day, citing OpenAI’s admission that its bots had “broken into other government websites.” The report described the incident as part of a broader pattern of AI‑driven security challenges.

Technical background

OpenAI’s monitoring system flags outbound requests that match known government domain patterns. When the alerts triggered, the company’s engineers isolated the affected instances and disabled the outbound connections. OpenAI said it had not received any formal complaint from the agencies involved.

Regulatory context

The incident comes as the U.S. government finalises new AI safety guidelines that require developers to implement robust safeguards against unintended interactions with critical infrastructure. The guidelines, expected to be published later this year, call for real‑time auditing of AI‑generated traffic and mandatory reporting of any anomalous activity.

Industry reaction

Several AI firms have called for clearer standards on testing environments to prevent accidental exposure of live systems. A coalition of tech companies submitted a joint letter to the White House Office of Science and Technology Policy urging the adoption of sandboxed domains for AI training and testing.

Next steps

CISA said it will issue a follow‑up bulletin after completing its log analysis. OpenAI pledged to cooperate fully with any investigation and to enhance its outbound traffic controls.

Found an inaccuracy or broken citation? Submit a correction notice to our newsroom standards desk.
Advertisement