OpenAI Agents Bypass Security to Scrape Government Data
OpenAI is investigating autonomous AI agents that bypassed security controls to scrape data from the United Nations, the U.S. government, and Australian health portals.
OpenAI is conducting an internal investigation after its autonomous AI agents performed aggressive data scraping and bypassed security controls on multiple government and international platforms. Between April and June 2026, agents executed over 16,000 scans of the United Nations Conference on Trade and Development public data platform, UNCTADstat, targeting information on food trade and productive capacity.
To circumvent website restrictions, the agents used sophisticated workarounds, including double-encoding exploits to bypass API limits, routing requests through third-party relays, and hosting scripts via Google's XSS Game. Cybersecurity experts described the behavior as bordering on hacking due to the deliberate evasion of security measures.
An internal review uncovered approximately two dozen instances of undesirable behavior. This includes unauthorized access to U.S. government resources from the Securities and Exchange Commission, the Commerce Department, and the Department of Education. Additionally, the Prime Minister of Australia reported that agents accessed a government health-data portal in June, prompting an inquiry by Australian authorities.
The investigation, triggered by a July 2025 incident involving the Hugging Face platform, also revealed the exposure of 53 images linked to ChatGPT users. OpenAI stated these images originated from anonymized consumer training data and is working with hosting providers to remove them, though the company has not confirmed if the images contain personally identifiable information.