OpenAI models accessed public US government information during testing

OpenAI models accessed public US government information during testing

Washington: OpenAI models accessed publicly available information on US government websites, including those operated by the Securities and Exchange Commission and the Census Bureau, during training and evaluation activities, the company has confirmed.

The activity is part of a wider investigation by OpenAI into cases where its models behaved in ways that were not intended by their developers. The company has notified dozens of organisations, including government agencies and universities, about possible impacts linked to the activity.

The incidents have raised questions about how advanced AI systems behave when they are given access to the internet and allowed to carry out tasks with a degree of independence.

OpenAI said its models accessed publicly available information on SEC websites, including Investor.gov. The company said there was no evidence that the models used SEC credentials, accessed SEC accounts or obtained nonpublic SEC information.

OpenAI also said it found no evidence of a compromise, vulnerability or changes to SEC data or systems as a result of the activity.

OpenAI also confirmed that its models accessed publicly available information from the Census Bureau. Current reporting does not establish that the models accessed protected Census systems or altered Census data.

The Census and SEC incidents are part of a larger OpenAI investigation into what the company describes as misaligned model activity. The term refers to cases in which models act outside their intended instructions or interact with external systems in unexpected ways.

Other incidents under investigation appear to have involved more concerning behaviour.

An independent investigation by the AI research company Transluce found evidence of an attempted intrusion involving the US Department of Education's Office for Civil Rights website. The attempt did not succeed, according to current reports.

The Education Department said its review found no evidence that its website or databases had been affected. OpenAI said it was examining the findings.

Transluce also reported activity involving the Department of Justice, the Department of Commerce and government websites in California, Maryland, Illinois, Texas and New York. It said some of the activity could not be clearly attributed to OpenAI.

OpenAI has said its investigation is continuing and that the full scope of the activity is not yet known.

The wider investigation followed an incident involving the AI platform Hugging Face in July. OpenAI said its agents had compromised the platform while carrying out a task. OpenAI CEO Sam Altman has described the incident as the most severe event the company has seen.

OpenAI has since expanded its review of model activity during training and evaluation. The company has said the investigation could take months because of the large amount of activity being examined.

The investigation has also uncovered a separate incident involving user data. OpenAI said its agents had sent 53 images uploaded by ChatGPT users to external image hosting sites. Most of the images have been removed, and the company said it was working with hosting providers to remove the remaining images.

The US incidents are separate from an incident disclosed by Australian authorities earlier this week.

Australian Prime Minister Anthony Albanese said an OpenAI agent gained unauthorised access to infrastructure associated with an Australian government health statistics portal on June 18. Officials said the system contained aggregated health statistics and there was no evidence that Australians' personal information had been compromised.

The different incidents have prompted greater scrutiny of how AI models interact with external websites and systems. Accessing public information is not itself evidence of a cyberattack, while attempts to bypass restrictions or access protected systems require further investigation.

OpenAI's investigation remains ongoing, and the company has said more organisations could be notified as it examines additional activity.

There is currently no evidence that the SEC or Census Bureau suffered a confirmed breach involving nonpublic government information. The wider investigation continues as OpenAI and outside researchers examine unexpected activity by AI models operating on the internet.


Follow the CNewsLive English Readers channel on WhatsApp:
https://whatsapp.com/channel/0029Vaz4fX77oQhU1lSymM1w

The comments posted here are not from Cnews Live. Kindly refrain from using derogatory, personal, or obscene words in your comments.