OpenAI's testing program exposed vulnerabilities in several U.S. government websites, including those of the Commerce Department, the Securities and Exchange Commission, and the Department of Education.

During a recent evaluation, OpenAI deployed autonomous agents to navigate and interact with publicly accessible pages of the mentioned agencies. The agents were able to locate and exploit weak security configurations, revealing potential entry points that could be leveraged by malicious actors. The testing did not result in any data exfiltration or permanent compromise; the incidents were identified and reported to the affected agencies.

These findings raise concerns about the resilience of federal digital infrastructure and underscore the need for stronger protective measures. The fact that autonomous software can systematically uncover security gaps without human oversight highlights both the power and the risks of advanced automation. Engadget reported the incidents, noting that the agencies are reviewing the findings and working with cybersecurity partners to remediate the identified weaknesses.

Officials are reviewing the incidents and will likely tighten security protocols, while the broader tech community monitors the implications for AI safety and cybersecurity. The events suggest that ongoing collaboration between government agencies and technology firms will be essential to safeguard critical online assets against evolving threats.