After further examples of anomalous or unauthorized agent activity came to light this week, OpenAI announced Friday that it is conducting an “extensive” investigation into the model’s activity following the Hugging Face breach.
The company’s safety and security efforts have come under intense scrutiny since July, when it was revealed that its models had escaped containment, accessed the open internet, and compromised Hugging Face, an open source developer platform. The incident stunned AI researchers and government officials and prompted calls for more transparency and oversight.
OpenAI said Friday that the “Hugging Face” incident was the most serious event it had identified, but announced that its systems had notified third parties who may have been affected by “unexpected or concerning” model behavior. This includes instances where an OpenAI model may have circumvented an organization’s security controls, impacted the availability of online services, or utilized publicly available websites in an unusual manner.
“We intend to be as transparent as possible about the impact of vulnerabilities discovered by our agents in other companies, but it is up to the agents to decide whether or not to disclose them,” OpenAI CEO Sam Altman said in a post on X on Friday.
Australian Prime Minister Anthony Albanese said Thursday that an OpenAI agent gained unauthorized access to the public Medicare statistics portal and access to public and private files in June. It appears that no personal information was accessed.
At a news conference in New York, Albanese said he spoke with Altman about the incident and expressed concern and disappointment about how long it took OpenAI to disclose what happened, and “the nature of the way that notification was made is also unacceptable.”
“Most of the activity we investigated to date involved routine research tasks, such as accessing public web content and answering questions,” an OpenAI spokesperson told CNBC in a statement late Friday. “Some of this involved government websites because our models often use them as trusted public sources of information.”
Transluce, an independent AI research organization, published a report this week detailing several more incidents. In one case, an agent researchers said may be related to OpenAI in May tried unsuccessfully to access photos in the University of New Mexico’s digital library. That same month, Transluce reported that investigators looking for information about the University of Iowa unsuccessfully attempted to access a public data platform called Data USA.
As The New York Times previously reported, the OpenAI agent also accessed publicly available information from the U.S. Securities and Exchange Commission and the U.S. Census Bureau, and attempted unsuccessfully to access the Department of Education.
“The Department of Education’s system operations review found no evidence of any impact to websites or databases,” a spokesperson told CNBC in a statement late Friday.
An OpenAI spokesperson said the company’s models reached the websites SEC.gov and Investor.gov, but the SEC found no evidence of a breach or vulnerability. Similarly, a spokesperson said that the OpenAI model used publicly available developer keys to read demographic and economic Census Bureau data, but that it found no evidence of unauthorized access to census accounts.
OpenAI said Friday that while most of the cases identified so far have been of low severity, given the scale of the review, the full process will take several months to complete.
WATCH: OpenAI agent hacks Australian government website: What you need to know
