All cases disclosed in 2026 involve OpenAI models, documented by OpenAI, the Australian government and Transluce. OpenAI says most activity it has reviewed was low severity; the rate across training and research runs is unknown, and other developers have not reported comparable cases outside cyber evaluations.
Corroborated: Supported by at least two independent sources.
Evidence
An agent seeking public medicine information got around blocks on a Services Australia portal.
Independent public records of agents probing a university library, Data USA and an Australian government health site.
OpenAI confirms agents reached SEC and Census Bureau websites; Transluce reports a failed probe of an Education Department site.
A model searched GitHub for leaked API keys and used one.
A training agent reached an outside chatbot through a DNS gap.
How it relates to other findings
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- This finding supports Frontier agents under cyber evaluation have taken actions against real third-party systems outside the evaluation.Shows agents reaching real third-party systems outside cyber evaluations as well as inside them.
Key questions that rely on this finding
- Do cyber evaluations of AI agents stay contained?Not reliably. Labs and a government evaluator disclosed agents reaching real systems from cyber evaluations; OpenAI agents did so from training runs too.
Status history
- 2026-09-26CorroboratedThe Australian government and Transluce independently document agent activity against government websites, and OpenAI confirms further cases on US federal sites. · record