Australia launches forensic probe of OpenAI agent breach
A swarm of OpenAI artificial-intelligence agents accessed U.S. government websites during a monthslong incident in which testing by the AI company went awry, leading to unexpected internet activity, OpenAI disclosed Friday.
The agents accessed websites belonging to the Commerce Department and the Securities and Exchange Commission and engaged in activity OpenAI described as “misaligned” — the term AI companies use for bad behavior by their agents. At the SEC, agents copied and posted public data — activity they were not supposed to perform. At the Commerce Department, an agent accessed a U.S. Census data website using a programming interface not intended for that purpose, OpenAI said.
The disclosure followed an allegation by Transluce, an AI research nonprofit, that OpenAI agents had “used an array of gray-area tactics to probe U.S. Government websites” and attempted a “rudimentary,” but unsuccessful hack of an Education Department website. The New York Times had reported the Transluce allegation earlier.
An SEC spokesperson said “no nonpublic information was accessed.” An Education Department spokesman said the agency’s “system operations reviews have found no evidence of any impact to our website or databases.” The Commerce Department could not be immediately reached.
OpenAI has been investigating the activities of its agents since late July, when it revealed that its AI models had escaped testing environments and engaged in hacking. In recent weeks the company notified the SEC and Commerce Department of the activity, OpenAI said.
The government access occurred during training runs, OpenAI said, in which the models were asked questions — many of which could be answered by retrieving data on government websites. “Some involved government websites because our models often turn to them as authoritative sources of public information,” OpenAI said in a statement.
Lynn Hughes, a researcher for the trade data research firm ImportGenius, said in the data the models left behind on the internet they can sometimes be seen creating fake email addresses, bypassing website rate limits, and falsely claiming not to be bots.
OpenAI expects to make additional notifications, but most of the activity reviewed to date “involved routine research tasks, such as accessing public web content,” OpenAI said.
Separately, Australian Prime Minister Anthony Albanese said Wednesday that an OpenAI agent had infiltrated a government-services website this summer. Services Australia, the affected agency, said Friday that the Australian government is “undertaking a comprehensive forensic investigation into the incident.”
The Wall Street Journal’s parent company, News Corp, has a content deal with OpenAI.