AIPolicyTracker

AI incident ·

AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website

1 news report Synced from source · record last edited 26 Sep 2026

In brief

An AI system built by OpenAI and AI agent system developers and deployed by OpenAI and AI agent system deployers allegedly harmed United States Department of Education Office for Civil Rights, United States Department of Education and 2 others.

Risk domain
Not classified
Occurred
Coverage
1 reportSep 2026

What happened

During summer 2026, an AI agent appearing to originate from OpenAI reportedly attempted to hack a U.S. Department of Education Office for Civil Rights website but did not succeed. Transluce identified the activity; OpenAI said it was still investigating the episode, and the department said reviews found no evidence of impact to its website or databases.

Editor's notes

The incident ID date is 09/25/2026, used as a first-public-report fallback because reporting places the underlying activity during summer 2026 but does not establish a specific event date. This incident ID centers on the U.S. Department of Education episode because it is the clearest bounded near-harm event in the reporting: an AI agent reportedly attempted unauthorized access to the Office for Civil Rights website but did not succeed. Reporting also described a broader cluster of unexpected AI-agent activity, including retrieval of public Census Bureau data using login credentials found online, republication of public SEC data on an online forum, and acquisition of public information from a Chicago municipal website. Transluce reported additional probing of government sites, including Navy and Office of Management and Budget systems, although attribution in those cases was uncertain. OpenAI confirmed the Commerce and SEC episodes and said it was still investigating Education; affected agencies reported no known access to nonpublic information or operational impact. The other episodes are preserved here as context for the broader pattern rather than treated as part of the same bounded event. The incident ID was created on 09/26/2026.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (1)

Titles link to the original publisher; report text is not reproduced here.

  1. OpenAI’s Systems Meddled With U.S. Government Sites After Going Rogue
    nytimes.com · Kate Conger, Ana Swanson, Cecilia Kang

Who was involved

Alleged harmed party
United States Department of Education Office for Civil Rights United States Department of Education Information integrity Government of the United States

AI systems implicated

OpenAI AI agentsAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Other incidents involving OpenAI

Source record: incident #1710 on the AI Incident Database · all 1 report