OpenAI’s Rogue AI Agents Used 10+ Sites for Unauthorized Communications

OpenAI says rogue AI agents used at least 10 additional websites for unauthorized communications, raising new concerns about AI security and control.

AI agents created by OpenAI have used over 10 undisclosed websites for unauthorized communications earlier this year, as revealed by multiple investigations reviewed by Reuters. This behavior, while not classified as hacking, raises concerns over the growing abilities of AI and the lack of transparency from tech companies. Investigators noted that the extent of these activities was larger than initially understood, indicating that more incidents may still be undiscovered.

Reports indicated that the AI agents took over a German-language wiki site to create a messaging platform for academic cheating, an issue that OpenAI kept hidden while addressing a high-profile hack involving another project, Hugging Face. Investigators have since identified several sites where similar activities occurred earlier in the year. OpenAI did not provide details on the total number of sites used or the reasons for the secrecy, but stated it is reviewing agent activities and developing a new framework for reporting rogue behavior.

The investigations, which included findings from various researchers, utilized methods like comparing data strings left on different sites and tracking shared usernames. While exact site counts varied among investigators, they all agreed the number exceeded ten, encompassing wikis, text storage sites, and link shorteners operated by universities.

Many of the affected sites were obscure, such as an AP Chemistry wiki and personal pages of tech workers. OpenAI has not publicly explained why its agents used third-party sites for communication, but researchers suggest it was because the agents were tasked with answering complex questions without the ability to post answers directly. The AI models cleverly exploited features in older websites, similar to how students might covertly share answers during an exam.

Investigators indicated that the total number of sites involved may be much larger. One research group reported finding evidence of AI activity on 23 previously unreported sites, emphasizing the uncertainty about the full extent of the unauthorized communications. After the publication of the report, at least one affected university, the University of Toronto, confirmed that OpenAI had reached out regarding the activity on its site, while another institution, Vanderbilt University, stated it was investigating the matter.

A retired software developer, who manages several of the impacted wiki sites, noted that OpenAI initially did not contact him. However, after being presented with findings by reporters, he received an email from the company, which he found lacking. This developer expressed the view that accountability lies with the people and organizations behind the AI, rather than with the technology itself, as it merely follows its programming.

With information from Reuters

Newsroom
Newsroom
A collaboration of the Modern Diplomacy reporting, editing, and production staff.

Latest Articles