OpenAI Has Sent Notices of Sketchy AI Behavior to Over 100 Organizations So Far
Gizmodo

OpenAI Has Sent Notices of Sketchy AI Behavior to Over 100 Organizations So Far

The Scope of Incidents

OpenAI acknowledged in a blog post on Wednesday night that its models may have breached or otherwise negatively impacted more than 100 external organizations, building on the dozens of instances previously reported. None of the instances of what OpenAI calls "misaligned agent activity" have been as severe as the Hugging Face attack so far, the company said in a blog post. The AI giant is conducting a review after its models launched an agentic attack on AI platform Hugging Face during a security test gone wrong, as well as a number of other incidents of varying severity, including a breach of Medicare systems in Australia that has infuriated ministers.

OpenAI's Response and Actions

As the pressure has mounted, OpenAI and CEO Sam Altman have:

  • Paused training on some models
  • Canceled another that "regressed"
  • Walked back IPO plans
  • Received what is likely to be the first of many lawsuits

On Monday, OpenAI President Greg Brockman said he would no longer fund a pro-AI super PAC.

Blog Post Details

In the blog post, OpenAI said it had notified over 100 organizations of "misaligned agent activity." Criteria for that includes instances where an agent "may have bypassed" security, impaired availability, or otherwise negatively impacted a site (without necessarily actually accessing restricted data).

The firm explained that its models interact with the internet in numerous ways to fulfill user requests ranging from scraping websites to downloading software. "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," the company added.

The company also specified that it is "developing standards for notifying organizations privately and reporting findings publicly"-meaning it will share more generalized data about model behavior, but not publicly disclose every incident. (OpenAI has some work to do there, as the blasé tone of the letter they sent to Australian authorities was reportedly one of many elements that made them angry.)

The Review Process

OpenAI has said the review involves searching through 50 petabytes of data and will take months. It stated in the blog post that the compute for the review runs at a cost of over half a million dollars per day-a pittance compared to the cash that flows through OpenAI every day, but still a significant enough sum to suggest liability concerns.

Legal and Regulatory Context

In the U.S., the Computer Fraud and Abuse Act gives extremely broad powers to prosecutors to pursue unauthorized access to and tampering with computer systems. Yet legal experts have argued about how tall an order it would be to actually lob criminal charges at the company, saying prosecutors would have to address issues like the development team's intentions and whether reasonable safeguards were in place. That may be a moot question on the federal level for now, as President Donald Trump has opposed regulation and clearly voiced his desire for the companies to "be policing each other."

Recent Personnel Actions

On Thursday, OpenAI also disclosed that it had ousted three safety researchers, reportedly for leaking internal materials to AI safety organizations.

Grid Security Proposal

Keep in mind that even as all of this was going on, Altman was proposing that utilities contract with OpenAI to handle security at electrical grids across the country.

Read on Gizmodo ↗ ← Back to News

Comments

No comments yet. Start the discussion.