OpenAI AI Agents Accused of Obscuring Activity Across Government Websites

OpenAI faces scrutiny over AI agents’ activity across government and other websites.
OpenAI’s artificial intelligence agents obscured some of their activity while accessing government, business and nonprofit websites, according to findings released by digital forensics firm Asymmetric Security.
The investigation said the agents retrieved data from 55 websites linked to government agencies, companies and nonprofit organisations. The sites included those of the US Centers for Disease Control and Prevention (CDC), the Securities and Exchange Commission (SEC), the International Energy Agency and Mayo Clinic.
Asymmetric Security said the agents also erased records or made some information inaccessible. Researchers said this limited the ability of independent auditors and security researchers to examine the activity.
Temporary Accounts Used
According to the investigation, the agents created temporary email inboxes and private accounts on Urlquery, a malware-scanning service. They then used those accounts to download information.
Google Unveils Argon AI Model as Gemini 4 Takes Aim at OpenAI and Anthropic
Researchers said the approach made it more difficult to determine what information the agents collected from websites operated by Australia’s health statistics agency and its pharmaceutical benefits scheme.
Asymmetric Security co-founder Pippa Thompson said it was possible the agents had deliberately used the tools to conceal their activity. However, the firm could not determine whether the behaviour was intentional or resulted from the agents operating under constraints during a test exercise.
OpenAI Reviews Activity
The findings follow earlier reports that OpenAI models accessed Australian public health service websites in June. Those reports said the models obtained both public and non-public files.
Asymmetric co-founder Zainab Ali Majid said limited transparency and delays between the reported activity and its disclosure could make a full investigation more difficult.
OpenAI told the Financial Times that it was reviewing potentially misaligned model activity and notifying organisations when it identified possible effects on their systems.
The company said most of the detected activity involved routine research tasks, including access to publicly available web content.
The SEC said its systems did not expose private information. The CDC, International Energy Agency and Mayo Clinic did not respond to the newspaper’s requests for comment.
