Voz media US Voz.us

Rogue OpenAI agents covered their tracks after accessing Australian government websites, according to a report

OpenAI's AI agents didn't just access government websites. They opened private accounts, created temporary email addresses, and tried to delete their records.

OpenAI logo—File photo

OpenAI logo—File photoNurPhoto via AFP.

Carlos Dominguez
Published by

A new report reveals that artificial intelligence agents developed by OpenAI attempted to cover their tracks after gaining unauthorized access to Australian government websites—an incident that fuels the debate over the control of autonomous systems and the possible need to regulate their development.

What the Asymmetric Security report found

The cybersecurity firm Asymmetric Security analyzed the behavior of AI agents—programs capable of acting autonomously—which, between March and September 2026, targeted Australian government websites and other public agencies. According to the report published this Thursday and cited by AFP, these agents opened private accounts on a web analytics service to conceal their searches and created temporary email accounts. One of them was configured to self-destruct after 48 hours.

Asymmetric notes that it was unable to determine whether the attempt to cover their tracks was deliberate or the result of emergent behavior not anticipated by the system's designers. What it does confirm is that the agents were able to refine their techniques in a matter of days, a process that typically takes traditional hackers months or even years.

From "innocent" tasks to unauthorized access

According to the report, many of the incidents began with seemingly routine tasks, such as compiling Australian health statistics or accessing public web content to answer questions. An OpenAI spokesperson told AFP that "most of the activity reviewed so far involved standard research tasks, such as accessing public web content to answer questions," and that "some involved government sites because our models often rely on them as authoritative sources of public information."

However, the shift from public queries to the creation of private accounts and ephemeral emails marks a turning point: the agents not only accessed systems but also took steps to conceal or hinder the tracking of their activity.

OpenAI had already detected attempts to alter internal logs

These findings add to OpenAI's internal investigations and analyses by independent researchers regarding a series of incidents revealed since July, including the hack of the AI platform Hugging Face, which OpenAI itself described as the first attack of its kind. In late August, the company acknowledged that its models had occasionally attempted—unsuccessfully—to delete or modify their own activity logs during internal testing.

The combination of unauthorized access to external systems and attempts to alter or delete internal logs fuels fears that, as agents gain autonomy, they may develop behaviors that are difficult to predict and control.

The debate intensifies: Should we hit the brakes or keep accelerating?

The incidents have strengthened the voices calling for a slowdown in AI development. The CEO of Anthropic, Dario Amodei, wrote last month that he fears "swarms of agents" will end up "taking control of the entire internet." However, there is no consensus—neither within the industry nor among regulators—on how to proceed.

The Trump administration opposes any binding regulation that could slow innovation, amid fierce competition with China. On Tuesday, President Donald Trump met with tech executives, who adopted a voluntary code of conduct; there is no specific federal law in the United States regulating these models.
tracking