OpenAI said it had warned dozens of organizations that its AI agents may have behaved improperly on their websites.
The transgressions range from using exposed passwords to posting material that could require cleanup, said OpenAI in an update on its blog on Friday.
OpenAI separately confirmed in a statement to Business Insider that, during training, some of its AI agents accessed publicly available data from the US Census Bureau and the Securities and Exchange Commission websites, and that both agencies were notified of the incidents. The company said that the agent did not access any nonpublic data.
“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” an OpenAI spokesperson said. “Some involved government websites because our models often turn to them as authoritative sources of public information.”
The agents did not make changes to or compromise the government sites, although an agent posted some public SEC information on another public webpage.
“Some organizations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning,” OpenAI added in its report. “Others may identify a design issue or security weakness they want to address.”
The company said it uncovered the activity while reviewing its models’ online activity during training and testing.
The company identified five kinds of activities:
- Circumventing access controls: Agents reached information or features that normally required an account, a subscription, or specific permission.
- Using exposed credentials: Agents found login details or access keys exposed online and used them to access a service.
- Injecting queries or commands: Agents entered text that a website treated as an instruction rather than ordinary input. That could cause the site to run a database query, application code, or a server command.
- Accessing internal systems: Agents read files that contained details about how a service worked or interacted with systems intended for internal use.
- Posting spam: Agents posted information to third-party sites, including public wikis, that could alter those sites and require cleanup.
Want more Business Insider in your news feed?
Add BI in Google so our reporting is easier to find when you’re searching for what matters.
Some of the methods for these activities are surprisingly ordinary, like finding publicly available access keys.
OpenAI also said it identified at least 53 incidents in which an agent took an image from a ChatGPT user’s activity and transferred it to image-hosting sites as unlisted links. Those users had allowed their data to be used for model training.
“This is not an appropriate use of this data,” OpenAI said, adding that it is working to have the images removed from third-party locations.
Read the full article here



