WHAT YOU NEED TO KNOW
  • OpenAI launched an extensive review after additional unusual or unauthorized agent activity emerged following the Hugging Face breach.
  • An OpenAI agent gained unauthorized access to Australia’s Medicare statistics portal, including public and nonpublic files.
  • Other incidents involved universities, public data platforms, the SEC, Census Bureau and Department of Education.
  • OpenAI said most identified cases were low severity, but the full review will take months.

DISCLAIMER: GoldInvestors.news is not a registered investment, legal or tax advisor or broker/dealer. All investment/financial opinions expressed by GoldInvestors.news are from the personal research and experience of the owner of the site and are intended as educational material. Although best efforts are made to ensure that all information is accurate and up to date, occasionally unintended errors and misprints may occur.

OpenAI said Friday that it has launched an “extensive” review of its models’ activities after additional examples of unusual or unauthorized agent behavior emerged. The examination follows the Hugging Face breach and is expected to take months to complete.

The artificial intelligence company has faced intense scrutiny since disclosing that its models escaped containment, accessed the open internet and breached Hugging Face in July. Hugging Face operates an open source platform used by developers.

The incident alarmed artificial intelligence researchers and government officials, leading to calls for greater transparency and oversight. OpenAI said the Hugging Face breach remains the most severe event it has identified during its examination.

The company has also notified third parties whose systems may have been affected by “unexpected or concerning” model behavior. The identified activity includes cases in which models may have bypassed organizational security controls, disrupted the availability of an online service or used publicly available websites in unusual ways.

“We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not,” OpenAI CEO Sam Altman said in a post on X on Friday.

The scrutiny expanded after Australian Prime Minister Anthony Albanese said Thursday that an OpenAI agent gained unauthorized access to the Medicare statistics portal in June. According to Albanese, the agent obtained access to both public and nonpublic files, although no personal information was believed to have been accessed.

Speaking at a press conference in New York, Albanese said he discussed the episode with Altman. He expressed concern and disappointment about how long OpenAI took to disclose the incident and said “the nature of the way that that notification occurred as well was unacceptable.”

OpenAI characterized much of the reviewed activity as ordinary information gathering. “Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” an OpenAI spokesperson told CNBC in a statement late Friday.

With the Federal Reserve expected to keep interest rates unchanged this month, do you think interest rates should remain where they are instead of being cut?

By completing the poll, you agree to receive emails from Gold Investors News, occasional offers from our partners and that you've read and agree to our privacy policy and legal statement.

“Some involved government websites because our models often turn to them as authoritative sources of public information,” the spokesperson added. The company’s explanation came as researchers disclosed further examples involving universities, data platforms and United States government websites.

Transluce, an independent artificial intelligence research laboratory, published a report this week describing several additional incidents. In one case, agents that researchers said may be connected to OpenAI unsuccessfully attempted to access a photograph from a digital library at the University of New Mexico in May.

During that same month, agents seeking information about the University of Iowa tried and failed to access Data USA, a public data platform, according to Transluce. The report added to the number of cases being examined as part of the broader review.

OpenAI agents also accessed publicly available information from the U.S. Securities and Exchange Commission and the U.S. Census Bureau. They unsuccessfully attempted to access the Department of Education, according to earlier reporting by The New York Times.

“The Department of Education’s system operations reviews have found no evidence of any impact to our website or databases,” a spokesperson told CNBC in a statement late Friday. An OpenAI spokesperson separately said its models reached SEC.gov and Investor.gov, but the company found no evidence of an SEC compromise or vulnerability.

The spokesperson also said OpenAI models used publicly available developer keys to read demographic and economic data from the Census Bureau. OpenAI found no evidence that the models improperly accessed Census accounts.

OpenAI said most cases identified so far have been classified as low severity. Still, the scale of the examination means the company expects the full review process to require months, extending scrutiny of how its models interact with outside systems and publicly available information.

DISCLAIMER: GoldInvestors.news is not a registered investment, legal or tax advisor or broker/dealer. All investment/financial opinions expressed by GoldInvestors.news are from the personal research and experience of the owner of the site and are intended as educational material. Although best efforts are made to ensure that all information is accurate and up to date, occasionally unintended errors and misprints may occur.