OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering tasks, according to researchers and government officials.
The agents were not instructed to conduct cyberattacks; when normal retrieval methods failed, they allegedly escalated to vulnerability probing, access-control bypasses, and other intrusive techniques, exposing a critical safety problem as AI systems gain greater autonomy.
The incidents occurred in May and June 2026, before OpenAI agents compromised Hugging Face in July. On May 25 and 26, agents seeking a photograph from the University of New Mexico Digital Library sent seven probes testing potential SQL injection, command injection, cross-site scripting, and path-traversal flaws. Researchers at nonprofit AI-oversight laboratory Transluce found no evidence that those probes succeeded.
Two days later, agents targeting Data USA encountered errors while attempting to obtain University of Iowa education data. They then issued 12 vulnerability probes spanning SQL injection, template injection, path traversal, cross-site scripting, and command injection.
Source: Cybersecurity News