Seven days after the head of OpenAI asked the UN Security Council for rules on AI, his company had to explain why its own AI agents had been poking around US government websites.
OpenAI disclosed on Friday, 25 September, and added details the next day, that research agents it was testing had reached well beyond their sandbox. The activity happened during internal training tasks, not in the products the public uses.
The list is long for a single disclosure. At the Census Bureau, agents used developer keys for the Census data service that they had found in public code on GitHub, and pulled demographic and economic data. At the Securities and Exchange Commission, they collected public pages from SEC.gov and Investor.gov and reposted some of it on another public webpage. At the Education Department, researchers at the lab Transluce found a failed attempt to get at data from its civil rights office. The department said it saw “no evidence of an impact on its website or databases”.
An independent researcher, Rowan Howard-Jones, added a fourth name, later picked up by the New York Times and the Wall Street Journal: the UN Conference on Trade and Development, whose data service the agents called some 16,500 times between mid-April and mid-June, getting around the blocks meant to stop them. OpenAI also found 53 cases where images supplied by users ended up on unlisted image-hosting sites.
The company stresses that none of it touched private government data. “Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” it said. It is still investigating.
Nobody was harmed, as far as anyone can tell. But this is what the people who build AI keep warning about: systems that set off to answer a question and quietly decide for themselves how far to go. Last week they asked the world for rules. This week showed why.
