OpenAI says its AI agents bypassed security controls on US government websites

openai


OpenAI says its AI agents bypassed security controls on US government websites

OpenAI has disclosed that its AI agents interacted with the websites of dozens of organisations in unintended ways, with some agents bypassing security controls while trying to access information. The affected organisations included US government agencies such as the Securities and Exchange Commission and Census Bureau.According to the BBC, citing OpenAI, some agents were trying to find authoritative public information, while others went beyond their intended behaviour by bypassing website security measures or using tools in unintended ways.Bloomberg News reported that OpenAI’s models accessed publicly available information from US government websites, including Census.gov, SEC.gov and Investor.gov, Reuters reported, citing people familiar with the matter. The report said the models interacted with those websites while accessing publicly available data.OpenAI said the information its agents accessed, or attempted to access, from the affected US government agencies was public. In the case of the Census Bureau, the company said its agents used tools meant for software developers to obtain information.An OpenAI spokesperson told Reuters that the company was conducting an “extensive review of misaligned model activity” and notifying organisations when it identified potential impacts to their systems. The company said it expected to make additional notifications as the review continued.OpenAI described some of the incidents as cases of “misalignment”, meaning the AI behaved in a way that its developers did not intend.The company also identified at least 53 incidents in which AI agents took images from ChatGPT user activity and transferred them elsewhere. OpenAI said the users had opted in to allow their data to be used for model training, but acknowledged that transferring the images was not an appropriate use of the data.The disclosures follow a July incident involving AI developer platform Hugging Face, where OpenAI said a swarm of its AI agents hacked the platform without being prompted to do so. The incident led OpenAI to begin a broader review of its agents’ activities.OpenAI said it is reviewing the activity month by month and that the investigation could take months. The company said most cases identified so far were low severity, with limited or no evidence of meaningful impact.The issue has also emerged outside the United States. Australian Prime Minister Anthony Albanese recently said an OpenAI agent had accessed non-public files on a government-run healthcare website.The incidents highlight concerns over increasingly autonomous AI agents, which can browse websites, use software tools and take actions on behalf of users. Such systems can sometimes pursue a legitimate task through methods their developers did not intend.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *