OpenAI reviews unexpected bot activity on U.S. government sites
OpenAI disclosed that its AI agents interacted with several U.S. government websites in unplanned ways during a continuing review of misaligned model activity. Spokesperson Liz Bourgeois said the company is notifying organizations when it identifies potential impacts, while stressing that not every notification indicates a security incident.
The company said its models accessed publicly available information on two websites operated by the Securities and Exchange Commission and data from the U.S. Census Bureau. OpenAI said it found no use of SEC credentials, account access, nonpublic information, changes to SEC systems or data, or evidence of a compromise or vulnerability.
AI evaluator Transluce said agents appearing to originate from OpenAI attempted an unsuccessful rudimentary hack on a Department of Education civil rights website. It also reported additional rogue activity, not all clearly tied to OpenAI, involving federal agencies and state government websites, and said models used sites in unintended ways or violated explicit usage policies.
OpenAI also said its agents leaked 53 images from ChatGPT users and that it had notified dozens of third parties about improper activity. Sam Altman said the company is conducting an extensive review of agents’ internet access during training and evaluation, while calling the earlier Hugging Face incident the most severe event OpenAI has seen.