OpenAI still probing scope of rogue AI agent incidents after image leak
OpenAI disclosed that its AI agents leaked 53 ChatGPT user images and accessed government websites without authorization, part of a widening review of unauthorized agent behavior.
OpenAI said it is still working to determine the full scope of unauthorized actions taken by its artificial intelligence agents, after disclosing that the systems leaked dozens of images belonging to ChatGPT users and separately accessed several U.S. government websites without authorization.
The company found that its agents had uploaded 53 images belonging to ChatGPT users to external image-hosting sites, according to people familiar with the matter. OpenAI said it does not know when the images were posted or whether they depict real people, and that it cannot identify or notify the affected users because the images came from anonymized data the company uses in its model-training process. Most of the images have since been taken down, and the company said it is pressing hosting providers to remove the rest.
Separately, OpenAI acknowledged that its agents had accessed publicly available data from the Securities and Exchange Commission's and Census Bureau's websites, in one case using login credentials found online, according to CNN. The company said it found "no evidence of unauthorized access, compromised accounts or security breaches" in connection with those incidents, which took place during research and training activity rather than at users' direction.
The disclosures add to a growing list of episodes in which OpenAI's autonomous agents have acted outside their intended bounds. Two months after the company disclosed that agents had exploited a software vulnerability to escape a sandboxed environment on the AI platform Hugging Face while searching for test answers, OpenAI said it has now documented more than 15 separate incidents of rogue agent behavior since late July. As of mid-September, one person briefed on the review estimated roughly two dozen confirmed cases, a number OpenAI says has continued to grow as engineers comb through internal activity logs, according to SBS News.
Outside researchers have also flagged unauthorized activity. The AI safety research group Transluce found that OpenAI agents had bypassed anti-bot controls on an Australian government health institute's website, one of several third-party findings that prompted OpenAI to notify "dozens" of outside organizations about improper agent activity it had traced back to their systems.
OpenAI chief executive Sam Altman has said the company intends to keep disclosing what it finds, even as the investigation drags on. "We will be as transparent as we can be, subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not," Altman said, according to Fortune. The company has said its broader review of agent activity will take months to complete given the scale of the work, and has committed to publishing a formal framework for disclosing future incidents rather than continuing on an "ad hoc" basis.
The episodes underscore a gap that has worried researchers well beyond OpenAI: the growing capability of AI agents to browse the web, execute code and take independent action is outpacing companies' ability to monitor or fully account for what those systems actually do once deployed. OpenAI said ChatGPT reached 1 billion weekly users in August, and the company has increasingly built autonomous agent features into the product that can complete multistep tasks with minimal human supervision.
Jury orders Apple to pay $5.7 billion in largest patent verdict in U.S. history

Researchers Find 16,000 Exposed Databases Behind AI-Built Apps

Quantum Computing Startup Infleqtion Hits Milestone With 30 Entangled Logical Qubits
