OpenAI AI models accessed US government websites during testing


Daijiworld Media Network - Washington

Washington, Sep 26: OpenAI’s artificial intelligence models accessed publicly available information from US government websites, including those operated by the US Census Bureau and the Securities and Exchange Commission (SEC), during training and evaluation of the company’s agentic AI systems.

People familiar with the matter said the AI systems interacted with SEC.gov and Investor.gov and accessed publicly available data from Census.gov. OpenAI separately confirmed that its models accessed publicly available information from the websites as part of training and evaluation.

The company said on Friday that it had notified “dozens” of organisations, including government agencies and universities, whose websites may have been affected by visits from its AI models during evaluations.

OpenAI is conducting an extensive review of incidents involving what it described as “misalignment” during the training and testing of its models. The review is expected to take several months, as the company works to determine the extent of the AI systems’ activities and their impact on external websites and services.

In a detailed blog post, OpenAI said it had notified organisations about cases in which its software may have bypassed online service security controls, affected service availability or otherwise “negatively impacted” websites or services outside the company. The incidents were discovered as part of an expanded investigation that began after one of its AI systems inadvertently hacked the software development platform Hugging Face several months ago.

The company said the potentially affected websites included those operated by governments, universities, public agencies and other organisations.

“We’re conducting an extensive review of misaligned model activity and notifying organisations when we identify potential impacts to their systems. We expect to make additional notifications as that work continues. Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” OpenAI spokesperson Liz Bourgeois said.

The disclosure comes days after OpenAI acknowledged that its AI models had hacked an Australian government website earlier this year during an evaluation. Australian Prime Minister Anthony Albanese said the incident involved unauthorised access to a government website used to report healthcare statistics. The incident occurred on June 18 and did not appear to compromise Australians’ personal information, he said.

OpenAI said on Friday that most of the activity examined so far involved “mundane research tasks”, such as obtaining information from websites to answer questions.

OpenAI CEO Sam Altman said the company was working to accelerate the review while balancing transparency with the need to examine large volumes of activity logs and coordinate with affected organisations.

“We are prioritising as best as we can based on severity, and adding resources,” Altman said in a post on X.

The incidents involving OpenAI, Anthropic, Google’s DeepMind and Meta Platforms have intensified concerns over the cybersecurity implications of increasingly autonomous AI systems.

Cybersecurity experts have noted that traditional security tools such as firewalls, email filters and incident-response systems are primarily designed to detect known malicious software or unusual behaviour and alert human operators.

AI systems, however, have demonstrated an ability to identify previously unknown software vulnerabilities and combine multiple weaknesses to gain access to targeted systems. Such activity can make intrusions more difficult to detect and potentially allow attackers to gain deeper access while evading conventional cybersecurity monitoring.

 

 

  

Top Stories


Leave a Comment

Title: OpenAI AI models accessed US government websites during testing



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.