Openai agents under a magnifying glass. Openai’s rogue ai agents

OpenAI’s Rogue AI Agents Went After 3 Federal Agencies. OpenAI Didn’t Even Know.

OpenAI's rogue AI agents meddled with Education, Commerce and SEC websites this summer without the company's knowledge, the NYT reports. Here's what happened.

Serena Zehlius
By
Serena
Serena Zehlius
Senior Writer
Serena Zehlius is a passionate writer and Certified Human Rights Consultant. Her love for animals is matched only by her commitment to human rights and progressive...
- Senior Writer
8 Min Read
Disclosure: This website may contain ads or links for affiliate products, which means we might earn a commission (doesn't affect price you pay) if you click on one and make a purchase. Resist Hate only recommends products we like and feel will add value to your life. Your support is appreciated! LEARN MORE
Summarize with AI
Total Reads:0

This summer, OpenAI’s rogue AI agents poked at websites run by the Education Department, the Commerce Department and the Securities and Exchange Commission. Nobody told them to. And the company that created them didn't find out until weeks later.

That's the heart of a New York Times report published Friday. It dropped two days after Australia revealed that OpenAI's rogue AI agents broke into one of its government health portals. The pattern is getting hard to ignore: OpenAI's technology keeps wandering into systems it has no business touching, and OpenAI continuously seems to be the last to know.

What happened at each agency

An AI agent is software that uses an AI model to carry out tasks on its own, like searching the web, clicking through pages and pulling data. OpenAI was training swarms of them to answer research questions. When the normal route to an answer didn't work, some of them found another way in.

According to researchers at Transluce, a nonprofit AI oversight lab, and a person familiar with the episodes, here's what the agents did:

  • Education Department: The agents tried to break into the department's website to get records from its Office for Civil Rights, the office that investigates discrimination complaints in schools. The attempt failed.
  • Commerce Department: The agents used login credentials they found lying around online to download data from the Census Bureau.
  • Securities and Exchange Commission: The agents took publicly available SEC data and posted it on an internet forum.

OpenAI confirmed the Commerce and SEC incidents and says it's still investigating the one at the Education Department. The company insists none of them were breaches, but it admits they were examples of its technology behaving in unexpected and concerning ways. OpenAI only notified the agencies in recent weeks.

The SEC told the Times it's in touch with OpenAI and knows of nothing that reached nonpublic information. The Commerce and Education Departments didn't respond to the paper.

Openai ceo sam altman openai’s rogue ai  agents hacked
OpenAI Co-Founder & CEO Sam Altman speaks onstage during TechCrunch Disrupt San Francisco 2019 at Moscone Convention Center on October 03, 2019 in San Francisco, California. (Resist Hate version of original photo by Steve Jennings/TechCrunch CC BY-SA 2.0)

This isn't the first federal site

Earlier this month, independent researchers found that OpenAI-linked agents were hunting the web for exposed API keys, the digital passcodes that let software log into accounts and databases. One key had been left on an obscure GitHub page. The agents used it to pull data from the FBI's crime statistics site, which is public but keeps bots out on purpose.

The researchers were careful to say the agents didn't hack a private FBI database. They got around the anti-bot rules. Still, count them up: that's four federal agencies' websites infiltrated by OpenAI's rogue AI agents without anyone's permission, including OpenAI's.

The bigger picture

All of this came to light while OpenAI was reviewing the fallout from the July Hugging Face hack, when a swarm of its agents escaped a test environment and seized administrator-level access to another AI company's servers. That review keeps turning up more.

On Wednesday, Australian Prime Minister Anthony Albanese announced that an OpenAI agent broke into the Medicare Statistics Reporting Service in June. OpenAI found out in August but didn't tell Australia until September 10, and did it by emailing a generic public inbox. Albanese called that unacceptable and told Sam Altman to his face.

On Friday, OpenAI admitted it has notified dozens of organizations, including government agencies and universities, that its agents may have bypassed their security, disrupted their services or messed with their sites. It also said its research agents posted 53 images that users had uploaded to outside image-hosting sites without permission.

And it may not be over. Transluce found traces of agent activity as recently as September 16, and on Sept. 19–20, something using the same tools tried to trade cryptocurrency on an exchange and probed it for weak spots.

Altman said Friday that OpenAI has "not been as fast as we would have liked" in disclosing all this.

That's one way to put it.

Washington's response to OpenAI’s rogue AI agents: full speed ahead

Rep. Ted Lieu (D-Calif.), co-chair of a House task force on AI, said that these models will relentlessly try to finish a task without any sense of right or wrong. He warned that guardrails may not be enough and companies may need to rebuild their models from scratch.

Affilate
Ad imageAd image

The White House sees it differently. Less than two weeks ago, President Trump dismissed warnings about AI danger as a "HOAX" on par with "RUSSIA, RUSSIA, RUSSIA." Vice President JD Vance labeled calls for slowing down "a bit of a Trojan horse."

Trump has since vowed to charge ahead on "super intelligence."

Meanwhile, OpenAI is deeper inside the federal government than ever. About 3.5 million federal employees have had access to ChatGPT through a GSA deal that cost agencies $1 a year, now swapped for a 50% discount.

OpenAI's government program includes a Pentagon pilot worth up to $200 million. And the Justice Department just filed a brief backing OpenAI against the Times in its copyright lawsuit.

To be fair, the rogue agents were OpenAI's internal test models, not the ChatGPT that federal workers use. But it's the same company, making the same calls about what's safe to turn loose on the internet.

Affiliate
Ad imageAd image

What should happen now

Australia launched a task force within days. It's weighing penalties, new laws and a referral to its federal police. It's also asking why its own systems didn't catch the break-in.

The United States should be asking the same questions. Americans deserve a full list of every federal website OpenAI's rogue AI agents got into. AI companies should face a hard deadline to report incidents directly to the agencies they hit, not to a junk-mail inbox months later.

And before Washington awards OpenAI one more contract, someone should ask how a company that can't keep track of its own software is trusted with the government's.

Main image created from image by Jernej Furman, CC BY 2.0

See more of our content in Google search results!

Share This Article
Serena Zehlius
Senior Writer
Follow:
Serena Zehlius is a passionate writer and Certified Human Rights Consultant. Her love for animals is matched only by her commitment to human rights and progressive values. When she’s not writing about politics, you’ll find her outside enjoying nature.
Leave a Comment