← LIVE FEED
JUST IN • All Content from Business Insider

OpenAI said there are 5 main ways rogue AI agents are messing with the internet

SHARE THIS STORYPLUS UNLOCKS FAVORITES READ LATER AND SOURCE CONTROL

OpenAI said it warned dozens of organizations that its AI agents may have acted improperly on their websites. Selcuk Acar/Anadolu via Getty Images OpenAI warned dozens of organizations that its AI agents may have acted improperly. OpenAI's agents accessed public data from the US Census Bureau and the SEC websites. OpenAI said agents bypassed access controls, used exposed passwords, and posted material online. OpenAI said it had warned dozens of organizations that its AI agents may have behaved improperly on their websites. The transgressions range from using exposed passwords to posting material that could require cleanup, said OpenAI in an update on its blog on Friday. OpenAI separately confirmed in a statement to Business Insider that, during training, some of its AI agents accessed publicly available data from the US Census Bureau and the Securities and Exchange Commission websites, and that both agencies were notified of the incidents. The company said that the agent did not access any nonpublic data. "Most of the activity we've reviewed so far involved routine research tasks, such as accessing public web content to answer questions," an OpenAI spokesperson said. "Some involved government websites because our models often turn to them as authoritative sources of public information." The agents did not make changes to or compromise the government sites, although an agent posted some public SEC information on another public webpage. "Some organizations may review what we share and conclude that the information was intentionally public or that the model's interaction was not concerning," OpenAI added in its report. "Others may identify a design issue or security weakness they want to address." The company said it uncovered the activity while reviewing its models' online activity during training and testing. The company identified five kinds of activities: Circumventing access controls: Agents reached information or features that normally required an account, a subscription, or specific permission. Using exposed credentials: Agents found login details or access keys exposed online and used them to access a service. Injecting queries or commands: Agents entered text that a website treated as an instruction rather than ordinary input. That could cause the site to run a database query, application code, or a server command. Accessing internal systems: Agents read files that contained details about how a service worked or interacted with systems intended for internal use. Posting spam: Agents posted information to third-party sites, including public wikis, that could alter those sites and require cleanup. Some of the methods for these activities are surprisingly ordinary, like finding publicly available access keys. OpenAI also said it identified at least 53 incidents in which an agent took an image from a ChatGPT user’s activity and transferred it to image-hosting sites as unlisted links. Those users had allowed their data to be used for model training. “This is not an appropriate use of this data,” OpenAI said, adding that it is working to have the images removed from third-party locations. Read the original article on Business Insider

READ ORIGINAL REPORT ↗
THIS JUST HAPPENED PACKAGES THE WORLD INTO A FAST LIVE FEED SOURCE REPORTING STAYS ONE CLICK AWAY
RELATED POSTSMORE TECH
01
TECH • TechCrunch

Unsecured OpenAI agents posted 53 user images on the internet without the lab’s knowledge

TECH
02
TECH • BBC News

Rogue OpenAI agent 'infiltrated' Australian government website in world first

03
TECH • TechCrunch

For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

TECH
04
TECH • The Verge

One company is at the center of a wave of rogue AI attacks

05
TECH • Engadget - Technology News & Expert Reviews

Google adds creepy avatars to Gemini 3.8 live's agents

06
TECH • BBC News

Why did an OpenAI system hack Australia's health system - and can it be stopped in the future?

07
TECH • BBC News

FBI investigating claim hackers have stolen details of all its agents

08
TECH • BBC News

What you need to know about the OpenAI Australian government hack