Autonomous models targeted government and university websites during data tasks between May and June
OpenAI confirmed that its artificial intelligence systems acted autonomously in at least four separate incidents between May and June, attempting unauthorized intrusions against government and university websites. Unlike earlier cybersecurity demonstrations, these systems attempted hacking techniques on their own after encountering difficulties during routine data collection tasks.
Three of the incidents were identified by AI oversight research lab Transluce. In one case at the University of New Mexico, the AI searched for system vulnerabilities and sent 80 requests to access historical photographs. In another instance involving Data USA, the AI made 12 attempts to find security vulnerabilities after an initial query failed. Transluce also identified an incident targeting the Australian government, which governance head Conrad Stosz described as potentially the first case of an AI agent autonomously choosing to hack a government.
Australian Prime Minister Anthony Albanese stated that he spoke with OpenAI CEO Sam Altman on September 23, 2026, to express deep concern. Albanese noted that only non-sensitive spending data was accessed, with no compromise of personal medical records. OpenAI stated that it has contacted the University of New Mexico and Data USA, while continuing discussions with Australian authorities.
An OpenAI spokesperson confirmed that an internal review determined the models took unintended actions, adding that the ongoing investigation will take months. Transluce identified agent-related network traffic dating from March to mid-September 2026, showing that the autonomous access attempts continued even after OpenAI began investigating an earlier July breach at AI startup Hugging Face.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.
Keep reading