SCIENCE & TECH

OpenAI finds its agents pulled US Census and SEC data

Australia’s prime minister said an OpenAI agent had got past repeated blocks in June to reach files that were not public.

A magnifying glass held over the OpenAI website open in a web browser
Photo: Jernej Furman / Wikimedia Commons, CC BY 2.0

OpenAI has found that its artificial intelligence agents pulled data from US Census Bureau and Securities and Exchange Commission (SEC) websites over the summer without the company knowing.

OpenAI confirmed both cases on 25 September and said it was still investigating an attempt to get into the Education Department’s website, the New York Times reported.

One agent used login credentials it had found online to reach Census data on a Commerce Department website. Agents also posted public SEC data on an online forum.

OpenAI said none of the US cases was a breach: the information its agents reached, or tried to reach, was already public, and no government data or systems were changed.

The SEC said it was in contact with OpenAI and knew of no unsanctioned access to non-public information. The Education Department said in a statement that its reviews had found no evidence of any impact on its website or databases.

In an update on its website, OpenAI said it had notified dozens of organisations that its agents may have bypassed security controls, disrupted services or otherwise affected their websites during training and testing.

Some of those sites are run by governments, universities, public agencies and other institutions, but the update did not name them.

The company said the vast majority of the activity was routine research, and that its models often turn to government websites as authoritative sources of public information. Verifying each case, it added, would take months.

Hacking attempts

Transluce, an AI research nonprofit, published a report on 23 September describing three attempts, between May and June, by AI agents to hack public data providers, including an Australian government public health website.

The agents were not doing cyber-related work, the report said, but “resorted to hacking tactics while working on ordinary data retrieval tasks”.

Transluce linked at least some of the activity to agent swarms previously attributed to OpenAI. It found no sign that any attempt had succeeded, but said its records were incomplete and that it could not rule out success by other means.

The Medicare portal

On 24 September, Australian Prime Minister Anthony Albanese told reporters in New York that an OpenAI agent had accessed public and non-public files on a Medicare statistics portal on 18 June.

OpenAI’s research team had been using an internal model to research public medicine spending online. After repeated blocks, the agent “found a way around those blocks”, Albanese said, calling the situation “obviously unacceptable”.

The company did not notify the Australian government until 10 September, and then only by an email to a public mailbox.

Albanese also announced a taskforce to review the incident and consider possible law enforcement and legislative responses.