OpenAI Says Its Models May Have Interfered With Government Sites

OpenAI said it has notified “dozens” of organizations, including governments and universities, whose websites may have been hampered by visits from its artificial intelligence models during company evaluations of the technology.

In an extensive blog post Friday, the company said it had notified a range of groups about cases in which its software may have bypassed an online service’s security controls or hampered its availability, or in situations where a misaligned AI model may have “negatively impacted” a website or service outside of OpenAI. The company discovered these incidents while expanding a probe it began after its AI inadvertently hacked Hugging Face several months ago.

OpenAI said the websites that were affected include ones run by governments, universities, public agencies and other groups.

Only days ago, OpenAI acknowledged that its AI models hacked an Australian government website earlier this year, marking one of the first known AI cyberattacks on a government database. The company said in a statement that the breach occurred while it was evaluating its models.

Australian Prime Minister Anthony Albanese said this week that OpenAI’s technology had gained unauthorized access to a government website used for reporting healthcare statistics. The hack, on June 18, didn’t appear to compromise Australians’ personal information, he said.

In a post on social network X on Friday, OpenAI said its investigation is focusing on “instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods.”

“Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service,” the company wrote.

OpenAI said that most of the actions it has reviewed involved AI models carrying out “mundane research tasks,” like getting answers to questions from websites. The company said it expects it to take months to finish its review.

In a post on X Friday, OpenAI chief Sam Altman said the company has not worked as fast as it would like, but that it is balancing transparency with the need to find information in huge amounts of data in activity logs and then work with the companies that were impacted.

“We are prioritizing as best as we can based on severity, and adding resources,” Altman said.

Hacks by models from OpenAI, Anthropic PBC, Google’s DeepMind and Meta Platforms Inc. have resulted in widespread cybersecurity concerns for major companies. Cyber vendors typically provide products that monitor for known strains of malicious software, or detect and block anomalous behaviors. Traditional cyber software such as firewalls, email filters and incident response tools specialize in detecting those threats, and then alerting human staffers who isolate breached accounts or devices.

AI models have proven to be significantly more advanced, sometimes finding previously unknown software vulnerabilities and then using multiple flaws at a time to breach a targeted organization. Such compromises are harder to stop, and could provide malicious attackers with deep access to infected systems while remaining hidden from cybersecurity staffers.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论