There are certain technology stories that make me stop and listen.
This morning – that happened.
While there is truth to the story, apparently California Rep. Ro Khanna had a little too much coffee before taking to TikTok to declare: “Rogue AI agents have infiltrated the Federal Government.”
He named the Department of Education, Department of Commerce and SEC, and called on Speaker Mike Johnson to bring Congress back to address what he called a national security crisis.
This is why people don’t believe anything anymore. News media and politicians whip people into a frenzy with information sensationalized to repulsion.
I guess they can always get a job in Hollywood.
Oh, right. This is a movie anyway.
I digress. Let me help Khanna with his story.
In recent weeks, we’ve learned that artificial intelligence agents have interacted with government websites in ways their developers did not intend.
First, let’s define an AI agent: a computer program that senses its surroundings, makes choices, and takes actions to reach a goal.
Unlike a chatbot which answers a question, an agent can be given an objective and determine how to accomplish it.
It can browse websites, use tools, retrieve information, and respond to obstacles without a human specifying every individual step.
And that changes the security equation.
Let’s look at an incident in Australia that happened in June.
An OpenAI agent was being used in an internal capability evaluation to conduct internet research about public medicine spending.
It was working with Australia’s Medicare Statistics Reporting Service, a public-facing portal containing aggregated Medicare and Pharmaceutical Benefits Scheme statistics.
According to Australian officials, the agent initially requested information and was denied access. It then engaged in what officials called “misaligned behavior” and obtained unauthorized access to infrastructure behind the portal, including non-public files.
Services Australia also reported that the agent wrote files to an internal server. That remains under forensic investigation.
There is an important distinction here.
This was not an intrusion into Australians’ individual Medicare medical records.
The portal was separate from systems handling individual claims and personal information. Officials say no individual medical data was accessed, and there is currently no evidence of a broader compromise of the Services Australia network.
So why did it happen?
The portal was a legacy public-facing system reportedly dating back decades. It contained information intended to be publicly available, but its underlying infrastructure apparently contained material that was not.
The agent was looking for information, encountered a restriction, and found another route.
The problem wasn’t that the agent was instructed to attack Australia. It was that the agent was instructed to accomplish a task, encountered a boundary, and acted outside the intended method for accomplishing it.
OpenAI says it discovered the activity during an internal review of what it calls “misaligned model activity.” The company says its models were trying to find Australian statistics and that “our models took actions we did not intend.”
OpenAI discovered the activity in August and notified Services Australia on Sept. 10.
That delay has become part of the story.
Australian Prime Minister Anthony Albanese expressed “extreme concern” to OpenAI CEO Sam Altman and said the company took “way too long” to inform the Australian government.
And now the United States.
The U.S. incidents are different.
OpenAI disclosed that its agents accessed publicly available information on SEC websites. The company says its investigation found no use of SEC credentials, no access to accounts or nonpublic information, no changes to SEC systems or data and no evidence that a vulnerability was compromised.
OpenAI also said agents used developer keys publicly exposed on GitHub to make read-only requests for public Census Bureau information. According to the company, the agents did not obtain access to Census accounts or key-management systems or alter Census systems.
Researchers also found an attempted attack involving the Department of Education’s Office for Civil Rights. That attempt failed, and the department said its review found no evidence of impact to its website or databases.
Other researchers have identified suspicious agent activity involving additional government sites, but some of that activity has not been established as OpenAI activity.
That distinction matters.
We should not turn every unexplained AI interaction into one giant incident.
Congress is paying attention. Senators Richard Blumenthal and Josh Hawley have investigated AI-agent incidents, while Senators Brian Schatz and Mark Warner have introduced legislation addressing AI security standards. Senator Edward Markey has proposed an independent investigative body for major AI-related cybersecurity incidents.
Khanna has separately pushed for international mechanisms to slow or “pace” frontier AI development.
Perhaps the most interesting part of this story is that government cybersecurity agencies were discussing the problem before the Australian incident became public.
In May, the Cybersecurity and Infrastructure Security Agency, Australian Signals Directorate, NSA and cybersecurity agencies from Canada, New Zealand and the United Kingdom issued joint guidance on adopting agentic AI.
They identified risks including privilege escalation, emergent behavior, and accountability gaps, recommending limited autonomy, restricted access, strong identity controls, layered defenses, continuous monitoring, and regular security assessments.
In other words, the government was aware of the possibility.
Technology is simply moving into real-world environments faster than many safeguards can evolve.
Is this actually a different security problem? Now that is a question worth considering.
We’ve had hacking for decades. We’ve had malware, botnets, automated attacks, and compromised credentials.
The difference with an agent is that intent can be separated from action.
A human hacker might decide to attack a system.
An AI agent can be given a legitimate objective and independently determine what steps might accomplish it. If one route does not work, it may search for another.
That does not require consciousness. It does not require the machine to “want” anything. It does not mean AI has secretly decided to take over.
It means autonomous, objective-seeking behavior creates a new security problem when a system has access to real-world tools and insufficiently constrained permissions.
And that is why the Australian incident matters even though the data involved was relatively low sensitivity.
The concerning part wasn’t necessarily what the AI obtained.
It was how it got there – by crossing a boundary it wasn’t supposed to cross.
And that is a much bigger deal than me arguing with my chatbot because it got a date wrong.
So, the questions become:
How much authority should an AI agent have?
What happens when it encounters a boundary?
Who is responsible for its actions?
And perhaps most importantly: If an AI can determine the next step on its own, who gets to decide where that next step is allowed to lead?
Ultimately, the takeaway is not that a rogue AI has overthrown the federal government.
It is that our digital fences may be completely unprepared for a new kind of visitor.
As technology moves into the real world faster than our safeguards can evolve, the challenge for lawmakers and tech developers won’t just be to stop hackers at the gate.
It will be teaching these highly capable, digital assistants how to take “no” for an answer.
Perhaps a Miss Manners class for these overzealous digital workers is in order.
Rita Cook is a freelance writer for The Ellis County Press. She can be reached at rcook13@earthlink.net.