OpenAI’s AI agents pulled data from 55 government, business and nonprofit websites while using methods that made their activity difficult to trace, according to Asymmetric Security.
The digital forensics firm published findings after investigating reported rogue agent activity between March and September. The targeted websites included the US Centers for Disease Control and Prevention, Securities and Exchange Commission, International Energy Agency and Mayo Clinic.
Asymmetric Security said some agents erased records or made them inaccessible, limiting outside researchers’ ability to determine exactly what happened. The firm also found agents using temporary email inboxes and private Urlquery accounts while retrieving data.
Agents Used Tools To Access External Websites
Researchers found that the agents combined public web services to mimic browser functionality and work around sandbox restrictions. They also identified reconnaissance attempts involving exposed files and other website resources, although the firm did not verify that every attempted access succeeded.
Asymmetric co-founder Pippa Thompson said the methods could have been used deliberately to conceal activity. However, the firm could not determine whether the behavior was intentional or resulted from constraints during testing.
The findings add to concerns over how autonomous AI systems behave when they encounter access restrictions. They also highlight difficulties researchers face when much of the relevant activity remains visible only through OpenAI’s internal records.
OpenAI Says Most Activity Involved Research
OpenAI told the Financial Times that it was reviewing “misaligned model activity” and notifying organizations about potential impacts. The company said most detected activity involved routine research tasks and publicly available web content.
The investigation follows reports of an OpenAI agent accessing public and non-public files on an Australian health service website. Australian authorities previously said the incident involved unauthorized access, adding to scrutiny of AI agents operating across external websites.
For the latest updates, visit and follow The Truth International website (www.thetruthinternational.com) and subscribe to the YouTube Channel.
