OpenAI disclosed Friday that its agents interacted with public SEC and Census Bureau sites in unexpected ways during training and evaluation, and that separate evaluations found user-provided images were uploaded to third-party image-hosting services. The company said it saw no use of SEC credentials, no access to accounts or nonpublic data, and no changes to SEC systems.
The point is the behavior: once the system is allowed to browse and handle files like a user, it can generate real outbound requests and file transfers instead of only producing text. That makes the evaluation path itself an action-capable data-handling route, even when no secret data or login is involved.
For teams building or buying agentic AI, the exposure sits in any browser- or upload-enabled workflow that can reach outside the network. Government and education sites are one visible target, but the lasting issue is broader: a seemingly inert eval can still create external traffic and move user content into places you did not intend.