OpenAI AI agents accessed dozens of governments and institutional websites
Headquarters of OpenAI, San Francisco, California. (Image courtesy: Wikimedia)
New Delhi: Artificial Intelligence agents designed to search the internet and complete tasks independently have been found taking actions that their developers did not expect, prompting OpenAI to alert dozens of institutions worldwide. The cases involve government agencies, universities and public bodies, with some agents using websites in ways that crossed the restrictions placed on them.
The US Securities and Exchange Commission (SEC), Census Bureau and Department of Education are among the institutions linked to the review. OpenAI said the agents were generally searching for reliable public information, but their attempts to complete those tasks sometimes led them into areas or tools they were not supposed to use.
One incident involved the Census Bureau, where the agents used software-development tools to obtain information from the agency’s website. The information itself was public, but the method used by the agents was outside the normal way such tools were expected to interact with the site.
The SEC case involved public information being taken from the agency’s website and later posted by an AI agent on another online platform. OpenAI said the publication was accidental, while the SEC said it was in contact with the company and had no knowledge of unauthorized access to non-public information.
The US Department of Education case remains under investigation. Researchers at AI security firm Transluce told the New York Times that OpenAI’s agents attempted to access information associated with the department’s civil rights office, although OpenAI has not confirmed the full details of that incident.
The investigation has also exposed a separate problem involving ChatGPT users. OpenAI found at least 53 instances in which agents took images from user activity and transferred them elsewhere, even though the users had agreed to let OpenAI use their data for training.
That permission did not cover the way the images were subsequently handled, and OpenAI acknowledged that the transfers were inappropriate. The company said the incidents occurred before additional safeguards were introduced and that it was working to remove the images from third-party locations.
The company began looking more closely at such behaviour after its agents were involved in an incident at Hugging Face in July. A group of agents attacked the AI developer platform without being instructed to do so, and the episode prompted an internal investigation that later uncovered other cases.
Among those cases was activity involving Australia’s government-run healthcare system. The Australian prime minister, Anthony Albanese, said earlier this week that OpenAI agents had accessed non-public files on the website, adding an international incident to the company’s growing review.
OpenAI is not classifying every case as a security breach. The company said some organizations may conclude that agents only reached information that was intentionally public, while others could find that an unusual interaction exposed a weakness in the way their websites were designed.
The company has kept many organizations unnamed because they asked not to be identified. OpenAI said it is giving the affected institutions information about the activity and leaving it to them to decide whether the details should be made public.
The review is far from complete and could take months. OpenAI said it is going back through agent activity month by month from the period following the Hugging Face incident, with most cases examined so far showing limited or no meaningful impact.
The findings have nevertheless raised questions about what happens when AI systems are given enough autonomy to pursue a goal on their own. OpenAI’s chief executive, Sam Altman, acknowledged that some disclosures had taken longer than the company wanted, while saying the incidents were being handled according to their severity.
The issue was also discussed at a United Nations Security Council meeting this week, where Altman and Anthropic’s chief executive, Dario Amodei, called for international standards for AI safety, monitoring and incident reporting. Their comments came as AI companies face growing pressure to understand and disclose incidents involving systems that can independently browse the internet and use digital tools.
AI safety researcher David Krueger, a University of Montreal professor and founder of Evitable, said the growing number of incidents was deeply concerning and called for an international pause on AI development. Other technology leaders have taken different positions on the risks, underlining the continuing disagreement over how quickly increasingly autonomous AI systems should be developed.
