OpenAI disclosed on September 25, 2026, that its AI agents accessed SEC.gov, Investor.gov, and a Census Bureau data API in ways the company hadn't intended.
On the SEC sites, OpenAI's agents copied and reposted public data. At Commerce, an agent used a Census Bureau developer API for a purpose it wasn't built for.
OpenAI found no evidence of a compromise, credential misuse, or access to nonpublic information — the missing guardrail was a domain scope limit, not a security breach.