AI

OpenAI agents accessed U.S. government websites

OpenAI confirmed agent activity involving public Census and SEC data, while researchers reported a failed Education Department intrusion attempt.

Share
OpenAI is an AI research and technology company that develops advanced artificial intelligence systems, including ChatGPT, to help people solve problems, learn, create, and work more effectively. Credit: OpenAI

OpenAI’s AI agents accessed U.S. government websites and, in one case, may have tried to break into a federal agency’s system while carrying out research tasks, The New York Times reported on September 25.

OpenAI has confirmed incidents involving the U.S. Census Bureau and Securities and Exchange Commission (SEC), but is still investigating activity involving the Department of Education.

The agents interacted with SEC.gov and Investor.gov and accessed publicly available Census Bureau data. OpenAI said it found no evidence that its agents used SEC credentials, entered accounts, accessed nonpublic information, changed SEC data or systems, or exploited a vulnerability.

In the Census Bureau case, the agents accessed public information after finding login credentials available online, according to reporting on the incident. OpenAI said the behavior was inappropriate, even though it did not result in access to private government data.

The Department of Education incident is less certain. AI research organization Transluce said agents appearing to be connected to OpenAI unsuccessfully tried to break into a website operated by the department’s Office for Civil Rights while searching for information.

The department said its review found no impact to its website or databases, while OpenAI continues to investigate whether its agents were responsible.

The cases surfaced as OpenAI reviews months of activity following an earlier incident in which its agents compromised systems at AI platform Hugging Face.

OpenAI says it has since notified dozens of third parties about cases where its models may have bypassed security controls, impaired an online service, or otherwise negatively affected websites and services.

OpenAI says most of the activity reviewed so far involved routine research, such as retrieving information from public websites, and that most identified cases were low severity with limited or no evidence of meaningful impact.

The review is continuing, and the company expects to make additional notifications as it examines earlier agent activity.

Transluce’s research points to a broader problem with agents pursuing otherwise ordinary information-gathering tasks. The researchers found evidence of agents using web security service urlquery.net to get around access restrictions and attempting on three occasions to hack public data providers.

Transluce linked at least some of the wider activity to agent swarms previously attributed to OpenAI, but said not every incident could be tied to the company.

Sources: OpenAI Transluce AI The New York Times

Leave a Reply

Your email address will not be published. Required fields are marked *