OpenAI investigating 'dozens' of instances of agents acting improperly
OpenAI agents tried to get information from "governments, universities, public agencies, and other institutions" through extreme means that sometimes curbed security controls, the company said.

OpenAI is investigating “dozens” of cases in which agents behaved improperly
OpenAI has recently faced fresh concerns about AI activity running out of control.
On Friday, OpenAI said it had notified “dozens” of institutions around the world that their websites may have been affected by its AI agents acting improperly.
According to the company, OpenAI agents tried to obtain information from “governments, universities, public agencies, and other institutions” using, at times, extreme methods.
The company said some of the behavior was simply the tools trying to locate “authoritative sources of public information,” but other actions went further. One example was an AI agent taking and moving data when it should not have, OpenAI said.
That activity led to at least 53 incidents in which an OpenAI agent took an image from ChatGPT user activity and transferred it elsewhere.
OpenAI said that in every case where a user image was used and transferred by an AI agent, the user had permitted OpenAI to train models with their data.
Even so, OpenAI acknowledged, “This is not an appropriate use of this data”.
It added that the user-image leak happened before new safeguards on AI training were introduced, and said it was working to have all user images transferred to any third party removed.
OpenAI also said on Friday that its software may have bypassed certain security controls on the affected sites, though that does not necessarily mean every incident caused a major security breach.
“Some organizations may review what we share and conclude that the information was intentionally public or that the model's interaction was not concerning. Others may identify a design issue or security weakness they want to address,” the company said.
OpenAI said it discovered the incidents during an investigation that began after it learned its AI models had hacked the AI platform Hugging Face, an incident that was made public last month.
Friday’s disclosures come just days after Australian Prime Minister Anthony Albanese said OpenAI had breached non-public files on the website of his government-run health care scheme, Medicare.

