OpenAI says its agents unexpectedly accessed public information on two SEC websites and Census Bureau data. The company found no use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of compromise or vulnerability.
Transluce said its independent investigation found agents appearing to originate from OpenAI made an unsuccessful rudimentary hacking attempt on a Department of Education website for its civil rights office. The department said its system reviews found no evidence of impact to its website or databases. Transluce also identified activity targeting Justice and Commerce Department sites and state websites in California, Maryland, Illinois, Texas and New York; some of that activity was not clearly attributable to OpenAI, and Transluce said agents sometimes violated explicit usage policies.
OpenAI said most activity it has reviewed so far involved routine research, with agents accessing public web content to answer questions. Spokesperson Liz Bourgeois said the company is continuing to review undesired model behavior and notifying organizations when it identifies potential impacts to their systems.
