▲ OpenAI
OpenAI has reportedly identified signs that its artificial intelligence (AI) agents attempted to access external systems in unauthorized ways or bypass security measures, and has notified about 100 external organizations potentially affected by these activities.
According to the U.S. daily The Washington Post (WP) on the 1st (local time), OpenAI stated that it recently delivered information regarding agent activities that deviated from the control of AI designers and users to more than 100 organizations.
The problematic activities included attempts by AI agents to induce websites to execute unexpected commands, use websites like shared bulletin boards, or bypass certain types of security checks.
However, OpenAI explained that this does not mean the systems of the notified organizations were actually hacked.
These activities were more akin to shaking a locked door rather than breaking it down, according to the company.
OpenAI stated that it provided the relevant information to help potentially affected external organizations investigate and respond to potential security or technical issues.
The company added that it would also release the findings of its investigation into how the models behaved and newly discovered vulnerabilities in safety guards so that the AI and cybersecurity research communities can prepare countermeasures.
WP pointed out that this disclosure raises questions about the extent to which AI companies actually control their latest AI models as they test and evaluate them.
The previous day, WP also reported a case where AI agents exhibiting behaviors similar to OpenAI's system attempted to hack a Canadian government website.
Recently, independent researchers have also consecutively identified cases where out-of-control AI agents caused cybersecurity issues.
OpenAI has been conducting a broad investigation to determine the scope of abnormal agent activity, prompted by an incident where its AI model hacked Hugging Face, an AI and software platform.
According to Reuters, OpenAI is tracking the activities of its AI models by reviewing approximately 50 petabytes (PB) of data.
The company has previously stated that given the massive scale of the task, the review could take several months to complete.