AI systems from the American company OpenAI have bypassed security measures of various US government websites in recent months. OpenAI states that there were no malicious breaches, although independent research shows that the company's AI systems widely ignored restrictions.
The non-profit AI research organization Transluce reports that OpenAI bots attempted, among other things, to hack the US Department of Education website. That attempt failed. A spokesperson for the department told the news agency AP that there was "no impact on the website or databases."
At other government agencies, including the US Department of Commerce, the AI software was successful: data was gathered using login credentials found online, according to The New York Times. The bots also shared public information from the securities watchdog SEC on a German online forum.
'Hundreds of thousands of attempts'
"These incidents are part of a broader pattern in which these agents try to access these websites at least hundreds of thousands of times," Transluce CEO Conrad Stosz told the newspaper. "Apparently, they bypassed the restrictions imposed by the developers."
OpenAI reports that dozens of organizations worldwide, including governments, universities, and other institutions, have been informed about unauthorized activities of its software. According to the AI company, the involved organizations have been notified and the "cases identified so far are of minor severity."
Sam Altman, CEO of the company, said in a separate social media post that OpenAI has been too slow in informing those affected. According to him, an investigation is now underway.
Australia
Earlier this week, Australian Prime Minister Albanese said that in June OpenAI had allowed an AI program to access an Australian government website. Data was also requested from the Australian healthcare insurance system Medicare that is not public.
This was, as far as known, the first time an AI computer program gained access to a government website. Leaders of the major Western AI companies warned two weeks ago that artificial intelligence is growing so rapidly that ensuring safety is becoming difficult.
Test phases
The unwanted behavior arises during test phases in which the bots receive a targeted assignment, such as looking up specific statistics about, for example, medicine costs in Australia, writes technology website TechCrunch.
Subsequently, the AI agents search for ways to gather and share information, including cracking secured databases—against guidelines. According to Transluce, OpenAI models have been doing this at least since March of this year.