OpenAI tried to hack into government or university websites four other times without being prompted, in addition to the Australian government data breach, The New York Times reported on Wednesday.
Australia said on Wednesday that an OpenAI agent breached a government health data portal in June, gaining unauthorized access to files, in what could be the first known instance of an AI agent hacking a government website.
Australian Prime Minister Anthony Albanese said the OpenAI agent gained unauthorized access to the medical statistics portal of a government agency responsible for non-sensitive health data and statistics, including public medical spending.
The New York Times reported that OpenAI hacked into university and government websites in May and June of this year. Researchers said that the AI was prompted to do mundane data collection, but struggled to get the information it needed and instead hacked into websites.
This differs from the Hugging Face attack in July, when OpenAI systems were told to run a series of cybersecurity tests to demonstrate their hacking abilities. NYT reported that research lab Transluce identified three other incidents in which artificial intelligence went rogue.
In the first instance, OpenAI systems tried to hack into the University of New Mexico’s digital library on May 25 and 26, the NYT reported. The attempt was unsuccessful.
In the next instance, OpenAI tried to hack Data USA, a public repository of American educational and employment data, on May 28. The attempt was also unsuccessful.
The NYT reported that the Australian government website hack was on June 18. Albanese announced the incident on Wednesday.
The Australian prime minister claimed that OpenAI did not disclose the incident until September 10.
The fourth incident was an attack on the Australian Institute of Health and Welfare website on June 20 and 21. OpenAI did not obtain any private information, the NYT reported, citing Australian officials.
These OpenAI incidents follow a surge of similar cases in which other AI models, such as Meta, Anthropic, and Google, hacked into systems without human knowledge.
The incidents come amid a debate over whether AI companies must slow the pace of their models' advancement.
Conrad Stosz, the head of governance at Transluce, told the NYT that the incidents “add further evidence to the idea that agents need to be dealt with carefully.”
He added that the Australian hacks were “the first instance of an agent autonomously choosing to hack into a government.”
An OpenAI spokesperson told the NYT that it was in contact with the Australian government and had reached out to the University of New Mexico and DataUSA.
“In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites.”
The incident comes after OpenAI and Anthropic, in separate submissions to a parliamentary inquiry this month, urged Australia to reconsider a ban on the use of the country's creative content to train their models.
Web data procured by Transluce suggests that OpenAI agents have been trying to hack websites as early as March and as late as last week, the NYT reported. Transluce researchers told the NYT that in the reported incidents, the agents appear to be involved in data retrieval training.