
So far, OpenAI has sent notifications of sketchy AI behavior to over 100 organizations
OpenAI acknowledged in a blog post Wednesday evening that its models may have violated or negatively impacted more than 100 external organizations, building on dozens of previously reported cases.
The AI giant is investigating after its models launched an agent attack on AI platform Hugging Face during a security test gone wrong, as well as a number of other incidents of varying severity, including a breach of Medicare systems in Australia that infuriated ministers. As pressure mounted, OpenAI and CEO Sam Altman suspended training on some models and canceled another that “regressed,” further scrapped their IPO plans and received what will likely be the first of many lawsuits. On Monday, OpenAI President Greg Brockman said he would no longer fund a pro-AI super PAC.
In the blog post, OpenAI said it had notified more than 100 organizations of “misaligned agent activity.” The criteria includes cases where an agent “may have circumvented” security, impaired availability, or negatively impacted a site (without necessarily actually accessing restricted data). The company explained that its models interact with the Internet in many ways to fulfill user requests, ranging from scraping websites to downloading software. “In some cases, models used Internet access unintentionally or, in retrospect, did not apply ideal restrictions,” the company added.
The company also clarified that it is “developing standards for notifying organizations privately and making results public,” meaning it will share more general data about model behavior but not publicly disclose every incident. (OpenAI has some work to do there, as the blasé tone of the letter they sent to Australian authorities was reportedly one of many things that made them angry.)
OpenAI said the review would involve searching through 50 petabytes of data and would take months. He said in the blog post that the review’s calculation costs more than half a million dollars a day — a pittance compared to the money that flows through OpenAI each day, but nonetheless a sum large enough to suggest liability concerns.
In the United States, the Computer Fraud and Abuse Act gives extremely broad powers to prosecutors to prosecute unauthorized access and tampering with computer systems. Still, legal experts debated how difficult it would be to bring criminal charges against the company, saying prosecutors would have to look into questions such as the development team’s intentions and whether reasonable safeguards were in place. This may be a moot issue at the federal level for now, as President Donald Trump has opposed regulation and made clear his desire for companies to “monitor each other.”
On Thursday, OpenAI also revealed that it had ousted three security researchers, apparently for leaking internal documents to AI security organizations.
Keep in mind that at the same time all of this was happening, Altman was proposing that utilities contract with OpenAI to manage the security of power grids across the country.
Gn bussni