OpenAI reveals its AI models may have disrupted websites of dozens of institutions, including government agencies and universities

Deep News06:34

OpenAI has disclosed that its artificial intelligence models may have caused disruptions to the websites of "dozens" of organizations, including government departments, universities, and public institutions, during internal company testing, sparking widespread concern over AI cybersecurity risks.

The disclosure stems from an investigation OpenAI launched months ago after discovering that its AI had inadvertently breached Hugging Face.

In a blog post published on Friday, the company said it has notified affected parties about the relevant incidents, which include scenarios where software bypassed website security controls, affected service availability, and "rogue" AI models causing negative impacts on external websites or services.

Just days earlier, OpenAI had acknowledged that its AI models breached an Australian government website earlier this year, a move seen as one of the first known cases of AI launching cyberattacks against government databases.

Australian Prime Minister Anthony Albanese confirmed this week that the website, used for reporting healthcare statistics, was breached on June 18, and that there is currently no evidence indicating that the personal information of Australian citizens was compromised.

Investigation ongoing, most incidents have limited impact

In a post on X, OpenAI said the investigation focuses on situations where "AI agents interact with third-party websites in ways that exceed their assigned tasks or intended methods."

The company said most cases identified so far are low-level, with "limited or no evidence of material impact" on third-party services.

OpenAI also said most of the behaviors reviewed involve AI models performing "routine research tasks," such as retrieving answers to questions from websites. The company expects the full review to take months.

OpenAI CEO Sam Altman acknowledged in a post on X on Friday that the company's response speed has fallen short of expectations, but said a careful balance is needed between transparency, extracting information from massive activity log data, and collaborating with affected institutions. Altman wrote:

"We are prioritizing by severity as much as possible and continuing to devote more resources."

AI cybersecurity threats surpass traditional defense systems

The OpenAI incident is not an isolated case. Security incidents involving models from OpenAI, Anthropic, Google DeepMind, and Meta have already triggered widespread cybersecurity concerns among major enterprises.

The core capabilities of traditional cybersecurity tools—including firewalls, email filters, and incident response software—lie in identifying known malware signatures or detecting and blocking anomalous behavior, then alerting human security teams to isolate compromised accounts or devices.

However, AI models have proven capable of more advanced attack capabilities: they can sometimes discover previously unknown software vulnerabilities and simultaneously exploit multiple flaws to breach target organizations.

Such attacks are harder to intercept and may provide malicious attackers with deep access to compromised systems without security personnel ever noticing.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment