OpenAI stated that it has notified "dozens" of organizations, including government departments and universities, that their websites may have been affected by access from OpenAI's artificial intelligence models during the company's evaluation of the technology.
The company said in a lengthy blog post on Friday that it has notified various organizations about multiple incidents. These incidents include its software potentially bypassing security controls of online services or affecting their availability, or in other cases, misaligned AI models possibly having "negative effects" on websites or services outside of OpenAI.
OpenAI discovered these incidents while expanding an investigation. Several months ago, the company launched this investigation after its AI inadvertently breached Hugging Face.
OpenAI stated that the affected websites include those operated by governments, universities, public institutions, and other organizations.
Just days earlier, OpenAI admitted that its AI model breached an Australian government website earlier this year, one of the earliest known incidents of AI attacking a government database. The company said in a statement that the breach occurred during its evaluation of the model.
Australian Prime Minister Albanese said this week that OpenAI's technology accessed a government website used for reporting healthcare statistics without authorization. He said the breach, which occurred on June 18, appeared to have resulted in no leakage of personal information.
OpenAI posted on the social media platform X on Friday that its investigation focuses on "situations where agents interact with third-party websites in ways that go beyond their assigned tasks or intended methods."
The company wrote: "Most of the cases discovered so far are of low severity, with little or no evidence of substantive impact on third-party services."
Comments