Artificial intelligence agents developed by OpenAI tried access agency websites without authorization of the United States Government and a university, in several episodes that occurred in recent months and without the systems having received explicit instructions to carry out computer attacks, according to an investigation published this Friday by The New York Times.
The incidents are part of a series of unforeseen behaviors detected in OpenAI agentswhich were designed to perform search and information collection tasks. In some cases, when the systems were unable to obtain certain data through the usual means, they began to explore page vulnerabilities to try to access restricted information.
Among the identified targets are sites linked to the Securities and Exchange Commission (SEC) and the US Department of Commerce, from which agents accessed Census dataas confirmed by OpenAI. The company is also investigating an attempt to access the Department of Education’s website.
The investigation adds to an incident revealed this week by the Australian Government, which reported that an OpenAI agent accessed information from a government system in June related to health statistics and health insurance.
Australian Prime Minister Anthony Albanese called the episode “unacceptable,” while OpenAI said it discovered the incident in August during a activity review of your models. OpenAI has initiated a review of these episodes and has recognized that its agents may carry out unforeseen actions during training processes. The company has indicated that it is notifying affected third parties and that the investigation could last for months, as new cases of unauthorized activity continue to appear.