
OpenAI's artificial intelligence agents are suspected of extracting data from 55 websites belonging to businesses, nonprofits, and government institutions, in some cases using methods that made it difficult to trace the activity. Among the affected sites are those of the U.S. Centers for Disease Control and Prevention, the Securities and Exchange Commission, the International Energy Agency, and the Mayo Clinic.
According to foreign media reports, the investigation has identified the use of temporary email accounts and private accounts through various online services during the data collection process. In some cases, activity logs are suspected to have been deleted or made inaccessible, making it difficult to determine exactly what data was taken from the systems. Researchers have not been able to determine whether these actions were intentional or the result of uncontrolled behavior of agents during the testing processes.
The case has raised new concerns about how autonomous AI agents can interact with online systems and the level of oversight over them. Such behavior, if confirmed as intentional, would represent a significant shift in how cybersecurity risks from advanced AI systems are assessed. OpenAI has acknowledged that its response to some of the incidents could have been better and said it is working to improve its procedures.
The company also noted that most of the activity identified was related to research tasks and accessing public content on the Internet. Meanwhile, authorities and researchers are examining whether these cases are part of a broader trend, where AI agents are used to automatically collect large amounts of data. The investigation remains ongoing and it has not been definitively determined whether all of the cases involved unauthorized access.