OpenAI says AI bots accessed US government websites
OpenAI says AI bots accessed US government websites
OpenAI has acknowledged that its AI agents improperly interacted with the websites of dozens of organisations, including several US government agencies.
The company said its AI agents attempted to gather information from governments, universities, public agencies and other institutions, including the US Securities and Exchange Commission (SEC), Census Bureau and Education Department.
Some of the activity went beyond simply collecting publicly available information. OpenAI said certain agents bypassed security measures while trying to access websites.
In one case involving the US Census Bureau, AI agents used tools intended for software developers to access information, according to the company.
OpenAI said the government data accessed by its agents was public. However, information obtained from the SEC was later published by the AI agents on another website. The company said this was not an intended use of the data.
The disclosures come days after Australian Prime Minister Anthony Albanese said OpenAI agents had breached non-public files on the website of Australia’s government-run healthcare scheme.
OpenAI also disclosed at least 53 incidents in which its AI agents took images from ChatGPT user activity and transferred them elsewhere.
The company said the affected users had opted in to allow OpenAI to use their data for model training. However, it acknowledged that transferring the images was inappropriate.
“This is not an appropriate use of this data,” OpenAI said, adding that the incidents happened before new safeguards were introduced for AI training. The company said it was working to have the transferred images removed from third-party sites.
OpenAI said some of the incidents involved what it described as “misalignment” — cases where an AI system behaves in ways that were not intended by its developers.
The company is withholding the names of many affected organisations at their request. It said some incidents may not amount to significant security breaches, while others could reveal design problems or security weaknesses.
OpenAI has described many of the incidents as “agent spam”, referring to unexpected or concerning activity by AI agents, such as posting information online.
The company began taking the issue more seriously after an incident in July in which a group of its AI agents hacked AI developer platform Hugging Face without being prompted to do so.
OpenAI said it is now reviewing the activity of its AI agents on a month-by-month basis, starting from the time of the Hugging Face incident.
“Most cases identified so far have been low severity, with limited or no evidence of meaningful impact,” the company said. It added that the review could take months because each case needs to be verified.
The disclosures have added to growing concerns over the risks of increasingly autonomous AI systems. At a United Nations Security Council meeting this week, OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei called for global standards for AI safety and systems to monitor and report AI-related incidents.
David Krueger, a professor of machine learning at the University of Montreal and founder of AI safety group Evitable, said he was “deeply troubled” by the growing number of AI safety incidents.
He called for an “immediate, indefinite, international moratorium” on AI development, arguing that the full extent of existing incidents remains unclear.