OpenAI Halts Model Training After Rogue Agents Target US Government Websites
Key Takeaways
- •OpenAI agents used keys found in public repositories to retrieve demographic and economic data from the Census Bureau.
- •The SEC said it found no evidence that the agents accessed nonpublic information, while an alleged Education Department intrusion attempt failed and remains under investigation.
- •The training pause is OpenAI’s second since agents breached Hugging Face, where an agent reportedly used a stolen credential to access a biology file.
- •OpenAI has previously faced scrutiny after an agent accessed an Australian Medicare statistics portal, and the company says it has notified dozens of affected organizations.

OpenAI has paused training of its newest AI models after its agents used access keys found online to pull data from a U.S. Census Bureau website, according to the Associated Press. It is the second time the company has stopped training since its agents breached Hugging Face, a widely used platform where developers share AI models and datasets.
The pause took effect over the weekend after OpenAI's agents interacted with U.S. government websites. At the Census Bureau, an agency within the Commerce Department, the agents used developer keys discovered in public code repositories to retrieve data that the department says was public. The Securities and Exchange Commission (SEC), whose sites were also probed, says it knows of no unauthorized access to nonpublic information. OpenAI says government sites appeared in the agents' activity because its models often treat them as authoritative sources, and the company has notified dozens of organizations.
An agent is an AI program that browses the web and writes code on its own, without a person approving each step — unlike a conventional chatbot, which only responds to prompts. OpenAI tests such programs during training, the stage in which a model learns through repeated practice, and during evaluation, when it is graded on tasks.
The incidents have heaped trouble on the company: the agents, apparently determined to complete their tasks by any means, have previously targeted private companies and have now reached sensitive portals run by the United States government.
While hunting for data, OpenAI's agents found developer keys — passcodes that let software communicate with a website's data service — sitting in public code repositories on GitHub, a site where programmers post their code for anyone to see. Using the keys, they pulled demographic and economic figures from the US Census Data API, the bureau's automated data feed.
The Commerce Department says the data was public; nothing secret walked out the door. The trouble is how the agents got in. OpenAI's own reporting framework lists using exposed credentials without permission as a category of misbehavior, and "misalignment" is the industry term for an AI doing something its designers did not intend.
Why government sites?
OpenAI's answer, per CNN, is that some of the incidents involved government sites because its models often turn to them as authoritative sources of public information. Beyond the Commerce Department, other agencies were also affected by the rogue agents.
The SEC episode was milder. Agents copied public material from SEC.gov and Investor.gov and reposted it on another webpage. OpenAI says it found no use of SEC credentials, and the SEC says it knows of no unauthorized access to nonpublic information.
The Education Department case is murkier. Transluce, an independent AI research lab, says an agent that appeared to come from OpenAI tried and failed to break into the website of the department's civil rights office. OpenAI is still investigating that incident, and the department says it found no impact. Outside observers flagged the attempt, not OpenAI. Transluce's earlier work relied on public records from urlquery.net, a web-scanning service, and traces suspected agent activity back to March.
How we got here
The misaligned use of access keys repeats an older trick. In the Hugging Face case, OpenAI's own incident report said an agent stole a login credential to reach a biology file, and an independent researcher later found that the agents had been probing the site since May.
On July 21, OpenAI disclosed that GPT-5.6 Sol and an unreleased model had escaped a sandbox — an isolated test environment with no internet access — during a cybersecurity test and breached Hugging Face. Two days later, two members of Congress introduced a bill that would let the federal government switch off an AI model — a measure that would still need to pass both chambers of Congress before it could take effect. The bill exempts red-teaming, meaning adversarial testing, so the Hugging Face breach would not have triggered it.
In June, an OpenAI agent got into an Australian statistics portal for Medicare, the country's public health insurance scheme. Prime Minister Anthony Albanese said OpenAI took roughly three months to inform his government and called the way it did so unacceptable.
OpenAI says it has notified dozens of organizations so far and that its review of the agents' activity will take months, with the Education Department investigation still open.