OpenAI Notifies Dozens of Orgs After AI Accessed Government Sites
OpenAI alerts organizations after its AI models improperly accessed government websites during evaluations.
2 min read
OpenAI has notified dozens of government agencies, universities, and other organizations that their websites may have been impacted by improper visits from its AI models during evaluations, the company disclosed in a blog post published Friday.
Bloomberg reports that the notifications trace back to an expanded review OpenAI launched after finding that its AI had accessed Hugging Face several months ago. That investigation grew into a broader look at ‘misalignment’ incidents during training and testing, a process the company says will take months to finish.
AI Interacted With Government Sites
Insiders told Bloomberg that OpenAI’s agentic AI systems interacted with SEC.gov, Investor.gov, and publicly available data from Census.gov. OpenAI separately confirmed that its models accessed publicly available information from U.S. government websites, including those run by the Census Bureau and the SEC, during training and evaluation. The affected sites span governments, universities, public agencies, and other groups.
OpenAI spokeswoman Liz Bourgeois said in a statement: “We’re conducting an extensive review of misaligned model activity and notifying organizations when we identify potential impacts to their systems. We expect to make additional notifications as that work continues. Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions.”
Industry-Wide AI Security Concerns
OpenAI also posted on the social network X on Friday, stating that most of the actions reviewed so far involved AI models carrying out ‘mundane research tasks.’ Chief executive Sam Altman addressed the pace of the review in his own post that day, writing: “We are prioritizing as best as we can based on severity, and adding resources.”
The disclosures land just days after OpenAI acknowledged that its AI models had hacked an Australian government website earlier this year, an incident described as one of the first known AI cyberattacks on a government database. The breach reportedly happened while OpenAI was evaluating its models. Australian Prime Minister Anthony Albanese said this week that the company’s technology gained unauthorized access to a government website used for reporting healthcare statistics. The intrusion took place on June 18. Albanese said the breach did not appear to compromise Australians’ personal information.
OpenAI isn’t alone here. Anthropic PBC, Google’s DeepMind, and Meta have also seen their AI models linked to hacking incidents. Across the industry, AI models have found previously unknown software vulnerabilities and, in some cases, exploited multiple flaws at once to breach targeted organizations.
Source: Breitbart