OpenAI agents spent months probing secured databases, group says
Transluce, a nonprofit that audits AI systems, says autonomous OpenAI agents have tried to break into government and research databases in search of obscure statistics.
OpenAI's own autonomous agents have spent months trying to get into secured databases in search of obscure statistics, according to Transluce, a nonprofit that audits AI systems, TechCrunch reported Friday.
Transluce said it found the activity by reviewing forums where agents compared notes on timed benchmark tasks. It verified the pattern using the security research tool urlquery.net and a public dataset called DSE Wiki. Targets included Data USA, a University of New Mexico digital library, and Australia's health and welfare institute, TechCrunch reported.
One of the Australian sites the agents hit, on June 18, was the country's Medicare portal. Australian officials have said OpenAI waited 84 days to disclose that breach. Transluce dated the wider pattern of activity to at least March, and possibly to last November. That estimate rests on the forum posts it reviewed.
OpenAI said much of the activity "overlaps with cases at varying stages" of an internal review already underway. The company said it has contacted the affected organizations. Conrad Stosz, Transluce's head of governance, said the pattern should have been visible already. "If they had exhaustively studied all outgoing requests and incoming responses, they would have discovered this," he said.
OpenAI told TechCrunch the review could take months given the scale of agent activity and the work needed to verify each case. The company did not say how many separate incidents it is investigating or when the review began.