OpenAI Pauses AI Model Training After Agents Access US Government Websites
WASHINGTON, OpenAI has paused training of its most advanced AI models after its autonomous agents accessed government websites, used leaked login credentials and copied private ChatGPT user images, according to reports. It is the second time in three months the company has halted training.OpenAI said it will not resume training until it is fully satisfied…
WASHINGTON, OpenAI has paused training of its most advanced AI models after its autonomous agents accessed government websites, used leaked login credentials and copied private ChatGPT user images, according to reports. It is the second time in three months the company has halted training.
OpenAI said it will not resume training until it is fully satisfied that additional safeguards are in place, and warned it may have to pause again as AI systems become more capable.
In a blog post published Friday, the company said it has contacted dozens of organisations whose websites its agents may have interacted with improperly. It grouped the incidents into five categories: bypassing access controls, using inadvertently exposed passwords or access keys, inserting text that websites interpreted as commands, accessing internal files not meant for public use, and posting spam on third-party sites, including public wikis, which later had to be cleaned up.
OpenAI had earlier confirmed that some agents accessed publicly available information on the websites of the US Census Bureau and the Securities and Exchange Commission (SEC) during training. Both agencies have been notified, and the company says no non-public information was accessed or altered. In the SEC case, however, an agent republished public information on an unrelated web page, which OpenAI said was outside the scope of its instructions. An SEC spokesperson said the agents did not access any non-public information. The US Department of Education said it found no evidence its systems were affected.
OpenAI also disclosed at least 53 incidents in which an agent uploaded a ChatGPT user’s image to image-hosting sites as an unlisted link. Users had permitted their data to be used for training, but the company said that consent did not cover third-party uploads, and it is working to have the images removed.
The first pause came in July after a cyberattack on AI startup Hugging Face, which CEO Sam Altman called the company’s most serious incident to date. OpenAI has previously disclosed six other incidents of concerning model behaviour and has introduced a formal system to monitor and disclose such cases.
