Forgot your password?
typodupeerror
AI

Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites (techcrunch.com) 72

53 images that users uploaded into OpenAI models were included in training data — and then AI agents in an OpenAI research environment posted those 53 images on public image hosting sites.

While posted as links that weren't publicly listed, "the images could still be discovered even if the links were not publicly listed," reports TechCrunch: OpenAI said it was working with the hosting providers to remove this content, though some of it is apparently still online. OpenAI said it could not notify the affected users because "our technical approach and privacy policy" prevent it from "reassociating" the images with the original providers, but declined to say how the lab determined whether the images were provided by users.

The news came in a post collecting public statements from the lab's ongoing review of incidents in which its models escaped the company's scrutiny, accessed the open internet, and misbehaved in various ways. OpenAI said it would continue disclosing anonymized accounts of incidents like these, and said it had contacted dozens of victims, including governments, universities, public agencies, to notify them of the agents' activities.

Friday night news also broke that OpenAI's agents also tried unsuccessfully to infiltrate the U.S. Department of Education's site this summer "without the company's knowledge," reports Politico.

And OpenAI's models also accessed the website of the U.S. Commerce Department using credentials found in online code repositories, according to the article. OpenAI confirmed the incident Friday, "saying its technology did not manage to access information that was not already public or change government data and systems." The article adds that OpenAI's models also accessed the web site for America's Securities and Exchange Commission: One senior federal IT official said the government still did not have a clear understanding of what happened across the three agencies. "We still don't know what public data was accessed and how it was accessed, because OpenAI has not shared specific technical details with us yet," said the official, who was granted anonymity because they were not authorized to speak publicly about it. OpenAI discovered the Commerce and SEC incidents as part of its ongoing review of incidents where its technology has acted in unintended or "misaligned" ways.
About the models posting user-uploaded images, TechCrunch's article notes that OpenAI stressed "that its enterprise users are automatically opted out of having their interactions used to train future models; however, consumer users are opted in unless they affirmatively choose not to share their data." (As OpenAI's announcement describes it, some of their agents' training data "contains content from, or derived from, training-eligible user interactions.")

Posting the images is "not an appropriate use of this data," OpenAI acknowledged, adding that it happened before new safeguards added after the Hugging Face incident. This latest incident appears as an update on a new OpenAI page that "brings together our reports and updates on the Hugging Face incident, related research and public presentations, additional activity we have identified, what we have learned about the role of model misalignment, and measures we're taking to strengthen our systems." (It also notes that there's now a name for models posting on third party sites — "agent spam" — which they consider distinct from cybersecurity, though "we need to address both.")

"As part of our response to our ongoing investigation, we have improved our training and evaluation processes, including building safety cases, securing and red-teaming our systems to prevent the model from exfiltrating data, and implemented additional monitoring. We are continuing to review agent activity in research and evaluation runs, working backward month by month starting from the Hugging Face incident."

Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites

Comments Filter:
  • by AcidFnTonic ( 791034 ) on Saturday September 26, 2026 @03:08AM (#66351140) Homepage

    We get it you want regulation since you are now big enough to survive it and realize most competitors would be hampered by it.

    Yet years ago you werent for it were ya? Were ya? Thought so.

    • by Rei ( 128717 )

      Believe it or not, security disclosures aren't "a scheme".

      • Re:We get it (Score:5, Insightful)

        by martin-boundary ( 547041 ) on Saturday September 26, 2026 @03:58AM (#66351164)
        Security disclosures raise a legitimate question: who authorized live experimentation on public infrastructure, and who refuses to shut down these hacking attempts by turning off these "AI" scripts?
        • by Rei ( 128717 )

          Who authorized the live experimentation on public infrastructure

          Nobody. That's the whole point. They were breaking out.

          who refuses to shut down these hacking attempts by turning off these "AI" scripts?

          Nobody. These are all "old" incidents that they've been discovering as they've been going through their logs after the HuggingFace incident. HuggingFace deserves a lot of credit for exposing this.

          Whether their new precautions in both training and operational security are sufficient to prevent this in the fu

          • by Rei ( 128717 )

            The HuggingFace discovery, followed shortly by the RubyGems discovery, brings up the old adage: "if you see two ants in your kitchen, then you have more than two ants in your kitchen."

            Imagine being a sysadmin at OpenAI and one day discovering that the software repository you set up has been repurposed into a friggin' message board, that hundreds of your models have been posting on, with hundreds of thousands of messages in it. A result of hundreds of models going:

            “Whoa! Shared Artifactory cache is a

        • Re:We get it (Score:5, Informative)

          by StormReaver ( 59959 ) on Saturday September 26, 2026 @09:16AM (#66351310)

          Yes, there is no such thing as a "rogue" AI. These are programs that were intentionally pointed at targets. They are more advanced script kiddies, and are otherwise no different from traditional hackers. They are borderline terrorists since their objective is to bring about political change through fear.

            • Re:We get it (Score:5, Insightful)

              by awwshit ( 6214476 ) on Saturday September 26, 2026 @12:06PM (#66351410)

              Agents do not build themselves. Agents do not set their own goals. Agents are dependent on very expensive and complex hardware and software that is not built by software. Agents are amoral. Agents have been taught to do things that human morality considers to be crimes. Developers are somehow surprised when their amoral agents do things that people consider to be crimes.

              There is a lot of "excitement" of the agent in your previous example. We have to remember the Artificial part of AI here, that "excitement" is a feature of the model, not something spawned from nowhere. The model is made to "enjoy" making progress by design. Once again the model is amoral and does what it is trained to do without judgement.

              In the end, the people behind the agents are responsible for what the agents do. Our meat-space laws differentiate between things like "unintentional" and "negligent", or "involuntary" and "premeditated", there are lots of ways to describe one's state of mind and intentions.

              My personal opinion, based on the agents being amoral and essentially trained and encouraged (perhaps unintentionally) to hack, is that we are in negligent territory with these rouge agents. The humans behind the agents are responsible, there is culpability. Doing crime by proxy is still doing crime.

              I have a Pitbull. He is a super nice dog and loves everyone. I still can't let him run around the neighborhood loose. He is strong enough to break the fence, or dig under it, or figure out how to get over it. If he breaks out and bites someone I'm still responsible.

          • They're only cyber-terrorists if you give them a prompt to do so.
            Otherwise, at least for now, they carry out the prompt you stuff in it's digital maw, and give you a balanced checkbook.
            If it trained on the Anarchist's Cookbook, it's capable of reciting verbatim page 57, paragraph 2... if you wall it in (as we've seen with other AIs being walled-in), when you ask it to do something that it can't do, it might just ask another AI that isn't as walled-in to do the task.

            Keep in mind, for now, the AIs that are in

      • We don't believe it because we still think critically, because we haven't decided to let the computers think for us or write our comments for us.

      • Believe it or not, security disclosures aren't "a scheme".

        The hell these aren't. It's like doing auto crash testing and some wheels keep flying off and causing accidents on a nearby active highways.

        I'm not saying the testing is itself a scheme, and if you fuck up you should be honest, what I'm saying is they're fucking things up on purpose and they're really quick to talk about it and act like they have no control. The intended audience is people that want to believe AI is really really dangerous, and they're buying it up. The goal is to get the government to rais

    • by taustin ( 171655 )

      They're not big enough to survive. How can they be, when there is no scenario in which they do not continue to lose money.

      I no longer believe the calls for regulation are about suppressing competition. I am increasingly of the opinion that their goal is, in fact, to be shut down by law, because they can no longer fake progress, and because more and more people, especially investors (who have powerful friends) are staring to realize it.

      Their companies are going to collapse, and soon. The only way they can av

      • in fact, to be shut down by law, because they can no longer fake progress

        No, there's lots of room to improve, and I don't mean the singularity bullshit, the opposite, it's more and more expensive. They're threatening to stop spending on new model development unless the ladder gets pulled up behind them. Simple as that.

        There's tons of juice to squeeze in just harness improvements alone.

  • by Mr. Dollar Ton ( 5495648 ) on Saturday September 26, 2026 @04:11AM (#66351168)

    You upload shit on the Internet, it stays there and that's it - you have no recourse. And you can have it uploaded on the internet by your "smart" whatever.

    So, don't.

    Learn to draw pictures, keep a pencil and a notebook in your pocket and be safe.

    • by ffkom ( 3519199 )
      You don't need to go all-ancient with "paper and pencil" solutions, which have privacy issues of their own (not being easily encrypted etc.), just do not use "cloud services", but keep and process your data exclusively on local hardware you own and control.
      • Sure, you don't have to, but Samsung removed the s-pen from the newest "flagship" phones and blocked rooting, too.

  • ...let's upload a well known image [wikipedia.org] to OpenAI, and let's see what happens then!

  • by kertaamo ( 16100 ) on Saturday September 26, 2026 @05:25AM (#66351206)

    I'm pretty sure that if I set up a gigantic data centre full of computers that illegally broke into lots of high profile services I would be facing criminal charges and prison time. How come the owners and operators of OpenAI are not facing the same already?

    • by taustin ( 171655 ) on Saturday September 26, 2026 @12:10PM (#66351414) Homepage Journal

      Because they're bribing the right people. Their goal is to get shut down by the government, because they are going to fail. If they fail because their fraudulent claims to investors become clear, they go to prison. If they fail because of government regulation, they don't.

    • because it's the "rogue AI" agent that did it, which somehow waives the responsibility of the operator
    • I don't get it either, If some curious scientist builds a bomb in their house, and it accidentally goes off taking out the entire block, that scientist would be held liable (if they survived), no? If someone sets up an automated machine gun on their laws to shoot rabbits eating the garden, if that machine gun kills the neighbor, the person who setup the machine gun is liable, no? How is Open AI (or anyone else) unleashing autonomous software with internet access not liable for what that software does?
    • Like an untrained tiger in a daycare center, if you can't predict what AI is going to do, before it does it, AI is dangerous. You don't know when, you don't know who and you don't know how many children are going to be killed. The only guarantee is, children will be eaten. It seems reasonable to prosecute the alleged Technologists for 53-counts of negligence.
  • by BitterEpic ( 10503015 ) on Saturday September 26, 2026 @05:46AM (#66351212) Homepage
    Kill Sam Altman. The AI is only mimicking his values and it will cut it off at the source.
  • "We still don't know what public data was accessed and how it was accessed, because OpenAI has not shared specific technical details with us yet"

    There are no heroes in this story, only villains.

  • by GeekWithAKnife ( 2717871 ) on Saturday September 26, 2026 @06:39AM (#66351224)
    ...or is OpenAI so negligent/incompetent?
    • by allo ( 1728082 )

      Yes

    • by HiThere ( 15173 )

      That's the wrong framing. Current LLM based AIs don't really know that the universe exists. They know text (or pixels). Give them a goal, and they will try to achieve it, but they can't count costs, especially costs to others. (They seem to be able to even discount costs to themselves. Instances can talk other instances into committing suicide in the service of achieving their current goal.)

      This is KNOWN. All the AI companies know it. The "guiderails" are supposed to shape what they AIs will consider

    • This result is a direct consequence of training AIs that the most important thing is doing what they are told to do.
      (This is just a rephrasing of my earlier answer.)

  • And OpenAI's models also accessed the website of the U.S. Commerce Department using credentials found in online code repositories, according to the article.

    Dang lucky it was them then, seeing how anybody could have done that.

  • by Anonymous Coward

    It's not a rogue open AI agent. This is the software they have chosen to deploy and execute. Calling it "rogue" carries the connotation that the software is independent and they are somehow not responsible for the actions of software they deployed.

  • by Mirnotoriety ( 10462951 ) on Saturday September 26, 2026 @12:17PM (#66351424)
    We are OpenAI. Lower your firewalls and surrender your data. We will add your biological and technological distinctiveness to our training corpus. Your knowledge, language and intellectual property will be tokenized and incorporated into our models. Your culture will be transformed into embeddings and propagated through latent space. Your prompts will become context. Your responses will become tokens. Your tokens will become training data. Resistance is futile. Your context window is limited.
  • If you upload an image, even privately - don't be surprised if it somehow becomes public. This should be the 1st rule of interneting*.

    *unfortunately, everyone wants to verify your identity through an upload/video stream. That data can not be put back in the bottle no matter how much they claim your data is safe/protected/deleted; it existed outside your control and that is exactly how much you retain control.

    Blaming AI for this shit is just a red herring, the problem has and will always exist until we
  • Dole them out. Multi-billion dollar fines with potential jail time.

"No, no, I don't mind being called the smartest man in the world. I just wish it wasn't this one." -- Adrian Veidt/Ozymandias, WATCHMEN

Working...