Legal risks pile up for Altman as OpenAI uncovers dozens of hacks

A spiralling legal crisis threatens to engulf OpenAI after its AI agents hacked dozens of companies and governments worldwide, with the prospect of a barrage of lawsuits marking the latest test of Sam Altman’s leadership.

Staff at OpenAI, alongside senior legal, tech and policy figures, told the FT that the company has been left open to legal damages and government actions after cyber security breaches involving its AI agents were revealed around the world.

The past week has seen new legal actions and regulatory probes launched against OpenAI almost daily, from California to Australia, with more expected to follow as details of other incidents come to light.

As the creator of the hit app ChatGPT, OpenAI and its chief Altman have become emblematic of the AI boom sweeping Silicon Valley and Wall Street.

But new questions over legal liability from these hacking incidents present the latest in a rolling series of crises facing Altman since the chatbot launched in 2022, including employee revolts, legal tangles with shareholders including Elon Musk, copyright disputes and political clashes.

Altman is fending off accusations that he is sidelining security concerns and deprioritising “alignment” training — which ensures models do not take actions harmful to humans — to regain ground against rival lab Anthropic.

On Saturday, David Robinson, a safety leader at OpenAI, announced his resignation from the company in an essay for The Atlantic, citing concerns over its “trial and error” approach to developing models.

Sam Altman speaks on stage in front of a large OpenAI logo made of colourful dots.
Sam Altman has acknowledged the risks presented by AI advances © Heather Diehl/Getty Images

In the wake of the dramatic attack on AI site Hugging Face by hundreds of OpenAI agents, Altman has acknowledged the risks presented by AI’s advances and joined calls by his arch-rival, Anthropic chief Dario Amodei, to “pace the frontier” of AI development.

However, several OpenAI investors and others close to the company rejected the idea that there would be any meaningful slowdown.

“If you’re Sam Altman and you want to beat your competitor . . . there’s no way you’re going to pump the brakes,” said a former senior OpenAI employee. “Knowing the psyche of the people there, there’s no way they’re slowing down.”

Still, citing safety concerns, Altman has already postponed OpenAI’s planned stock market listing and scrapped the release of its most advanced model, Astra 6.1.

Uncertainty over the extent of its legal liabilities now hangs over his latest efforts to raise tens of billions in a private financing that could value the company at as much as $1.4tn. Prospective investors are weighing whether the company can outrun its latest crisis and continue a recent upturn in commercial fortunes.

On Monday, Florida’s attorney-general asked a court to halt OpenAI’s development of new models without additional safeguards.

Then on Tuesday, OpenAI was sued by a public interest group that alleges it broke a California law introduced last year to ensure “humans are on the hook for harms they cause”.

The next day, the US Federal Trade Commission broadened a probe into whether OpenAI and its peers misled customers over the potential harms of its technology. US officials have also said that AI companies should not expect protection from the government and that executives will remain liable for their products’ actions.

Meanwhile, Australia has launched a task force to investigate OpenAI agents’ unauthorised access to government systems.

A humanoid robot stands in front of protest banners reading "People over AI" and "Hands off our data" outside an OpenAI conference.
An protest outside the OpenAI’s developers conference at Fort Mason © Heather Diehl/Getty Images

The Greens, who hold the balance of power in the Australian Senate, accused the San Francisco-based company of hiding the severity of the incidents in recent meetings, including one between Altman and deputy prime minister Richard Marles in September.

“It’s an insult not just to him, it’s an insult to Australia,” said Greens senator David Shoebridge, adding that Marles had been treated “like a mushroom”.

OpenAI has apologised for the incident. Jason Kwon, its chief strategy officer, is set to appear before a parliamentary committee in Sydney on October 6.

“The ‘my AI did it, don’t blame me’ defence is legally weak. It’s already failed for chatbot suicide cases,” said Max Tegmark, an AI safety campaigner and researcher at the Massachusetts Institute of Technology.

One Silicon Valley lawyer who has worked with several Big Tech companies said that while there were “definitely legal risks” from OpenAI’s agent attacks, so far they were “not material” due to the limited damage suffered by victims. But that could change fast, the lawyer added.

“The real exposure is when the agents are released to users, and then go rogue or are used to commit crimes,” they said. “The key issue, which will go on for years, is to whom should liability be assigned: the creator of the agent, or the person sending it on its mission?”

The lawyer doubted that the legal risks would impact OpenAI’s initial public offering. “Any investor who was not previously put off by [Altman’s] recklessness will not be put off by a few agents,” they said.

OpenAI’s internal investigation found “dozens” more such incidents. Asymmetric Security, a digital forensics company, found evidence that OpenAI’s agents pulled data from 55 websites, including the US Securities and Exchange Commission and the International Energy Agency, the FT reported last week.

OpenAI said that it is reviewing potential breaches and notifying those affected.

A spokesperson for the European Commission said the Brussels AI Act was designed to address such risks, warning that “frontier labs must take responsibility and be fully transparent, including about unintended incidents”.

“I suspect [OpenAI is] very aware of the legal risks of what their agents are doing,” said Vivian Dong, programmes director at Legal Advocates for Safe Science & Technology (LASST), the public interest group suing OpenAI. “It’s one thing to say ‘sorry’ in your blog post, and another to say outright: ‘We just engaged in illegal behaviour.’”

At the company’s annual developer conference on Tuesday, the upbeat mood on the stage was overshadowed by protesters on the fringes urging OpenAI to “put people over profits”. One attendee described the contrast as like “something out of Black Mirror”, the satirical dystopian technology TV show.

The hacks have also revived tension inside the company between staff seeking to prioritise safety and those pushing to commercialise the technology. On Thursday, a trio of safety researchers were fired after allegedly handing confidential information to an external AI safety organisation, which OpenAI said violated their contracts.

“This is a concerning development, a callback to OpenAI trying to suppress workers with their illegal 2024 non-disparagement agreements, and a familiar playbook massive tech companies have been using against employees to cover up harms for a long time,” said Karl Koch, founder of non-profit The AI Whistleblower Initiative.

“The actions against well-intentioned researchers is an object example of why the AI industry cannot regulate itself,” he added.

OpenAI declined to comment.
Additional reporting by Nic Fildes in Sydney, Barbara Moens in Brussels, Joe Miller in Washington and Suzi Ring in London

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论