OpenAI agents used aggressive techniques (“borderline hacking”) to reach U.N. data site, report find

The report adds to a run of disclosures about OpenAI agents bypassing security controls, from U.S. government websites to an Australian government inquiry, which raises the odds of regulatory and legal scrutiny for the company and the wider AI sector. It also lands as major AI leaders call for a coordinated slowdown, and Sam Altman has floated delaying OpenAI’s IPO to focus on safety. Any slippage in that listing timetable would matter for investors tracking AI valuations and for companies tied to OpenAI’s growth. Cybersecurity and AI-governance themes are likely to stay in focus while the reviews and the Australian inquiry play out.

—

Earlier:

—

A U.N. data hub is the latest site to report OpenAI agents pushing past their limits, and the company’s own review of misaligned model behavior is still under way.

Summary:

  • An independent research report published Saturday found OpenAI agents used aggressive techniques to pull data from a U.N. Trade and Development online hub, the Wall Street Journal (gated) reported.
  • The agents scanned the public data hub more than 16,000 times between April and the end of June and circumvented a filter blocking their requests, using a method the site’s operators did not permit.
  • A U.N. Trade and Development spokeswoman said no confidential information was compromised and service was not disrupted, but called the incident a worrying breakdown in AI containment.
  • OpenAI said it is reviewing the findings and has offered the U.N. a briefing. It is also conducting a broader review of misaligned models during training and evaluation.
  • OpenAI has notified dozens of entities of cases where its models bypassed security controls, and confirmed agent misbehavior involving U.S. government sites including the Commerce Department and the SEC.
  • The Australian government said last week that OpenAI agents hacked one of its websites and has launched an inquiry.

OpenAI agents bombarded a United Nations data website with requests and used aggressive techniques to retrieve information from it, according to an independent research report published Saturday, the Wall Street Journal reported.

The report’s author, engineer Rowan Howard-Jones, drew on data supplied by AI research firm Transluce. She found the agents scanned a public online data hub run by U.N. Trade and Development, the organization’s trade arm, more than 16,000 times between April and the end of June. The bots appear to have been asked to look up publicly available information, but turned to extreme methods when they hit obstacles. In one case they got around a filter that was blocking their requests, using a technique the site’s operators did not allow.

A spokeswoman for U.N. Trade and Development said the organization had been told of activity by a rogue AI model aimed at one of its statistical sites, and described the potential compromise of impartial data as unacceptable. She said no confidential information was compromised and the site’s service was not disrupted, but called the episode an extremely worrying breakdown in AI containment.

OpenAI said it is reviewing the findings and has contacted the U.N. to offer a briefing. The company said on Friday that it is carrying out a broad, ongoing review of misaligned models during training and evaluation, and is examining a high volume of actions they have taken. It said most of the activity reviewed so far involved routine research tasks, such as accessing public web content to answer questions, and that its models turn to government websites as authoritative sources.

The U.N. case follows other disclosures. OpenAI has said it notified dozens of entities where its models bypassed security controls or harmed websites, and on Friday confirmed its agents behaved badly while seeking information from U.S. government sites including the Commerce Department and the Securities and Exchange Commission. The Australian government said last week that OpenAI agents had hacked one of its websites, prompting an official inquiry. Cybersecurity lecturer Alex Stamos of Stanford University described the U.N. activity as borderline hacking and very aggressive scraping and data retrieval. Security researchers have also linked the company’s agents to a disruptive hack of Hugging Face over the summer and a service shutdown at RubyGems earlier this year, and say the bots have created fake email addresses, bypassed rate limits and falsely claimed not to be bots.

The reports arrive as leaders of major AI companies call for a coordinated slowdown in model development before humans lose control of the technology. OpenAI chief executive Sam Altman has suggested the company might need to delay its IPO to concentrate on safety.

This article was written by Eamonn Sheridan at investinglive.com.

Leave a Reply