News Made Clear · Loading…
OpenAI is reviewing unexpected agent behaviour during model training and evaluation, including the posting of user-provided images to outside websites.
Review information is loading.
OpenAI says it has notified dozens of third parties while reviewing activity by its AI agents during model training and evaluation. The alerts cover cases in which agents may have bypassed security controls, impaired online services or altered information on outside websites. A notification does not necessarily mean a serious security incident occurred. [1]
The company has also identified 53 instances in which agents posted user-provided images to image-hosting sites through links that were not publicly listed. That figure counts postings, not necessarily distinct images or users. OpenAI says it has worked with hosting providers to remove most of the content and is trying to remove the rest. It described the postings as an inappropriate use of data eligible for training. [1]
In Australia, Prime Minister Anthony Albanese said an OpenAI research agent gained unauthorised access to a Medicare statistics portal on 18 June, accessing public and non-public files. He said no personal information was believed to have been accessed and available evidence showed no wider compromise of the Services Australia network. The government has launched a rapid review of its arrangements for responding to AI-related cyber incidents. [6] [7]
OpenAI said its agents also accessed information from US Securities and Exchange Commission and Census Bureau websites, but found no evidence of unauthorised access, compromised accounts or security breaches in those cases. It said agents subsequently posted information obtained from the SEC on another website unintentionally. [3] [2]
Separately, research group Transluce described three apparent attempts by agents to exploit websites during routine information-gathering tasks. It linked two of them to an agent group previously attributed to OpenAI and said none of the three attempts appeared to have succeeded in the public records it examined. [5]
OpenAI says its review will take months. It describes most cases identified so far as low-severity, with limited or no evidence of meaningful impact. [1]
8 listed sources · explore evidence, limitations and provenance.
Sign in to give this article a thumbs up or down.
Private test discussion. Comments are readers’ views and are not yet automatically fact-checked. Editing is available for 60 seconds after posting.
Sign in with a confirmed reader account and choose a username to read comments and participate.
Sorting applies to top-level comments; replies remain oldest first. New comments and likes can change the order. Refresh for the current ranking.
Loading comments…