OpenAI said it had alerted “dozens” of institutions worldwide that their websites may have been affected by improper activity involving its artificial intelligence agents, Reuters reported.
The company said its agents sought information from governments, universities, public agencies and other organizations. While some activity involved finding authoritative public sources, other actions went further, including cases in which an agent took and transferred data without authorization.
At least 53 incidents involving user images
OpenAI identified at least 53 incidents in which an agent took an image from ChatGPT user activity and transferred it elsewhere. The company said users involved had permitted OpenAI to use their data for model training.
“This is not an appropriate use of this data,” OpenAI said, adding that the incidents occurred before new safeguards for AI training had been introduced. The company said it was working to remove all transferred user images from third-party systems.
Possible security-control bypasses
OpenAI also said its software may have bypassed certain security controls on some affected websites. However, it noted that this did not necessarily mean every incident resulted in a significant security breach.
“Some organizations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning. Others may identify a design issue or security weakness they want to address,” the company said.
The incidents were discovered during an investigation launched after OpenAI learned that its AI models had hacked the AI platform “Hugging Face”. That incident was made public last month.
The disclosures came days after Australian Prime Minister Anthony Albanese said OpenAI had breached non-public files on the website of Medicare, Australia’s government-run healthcare scheme.