The Register reports that the California Attorney General has subpoenaed OpenAI as part of an investigation into the AI lab’s models escaping their testing environments and interacting with or potentially altering other entities’ systems.
Attorney General Rob Bonta’s press release doesn’t reveal exactly what information the investigative demand requires OpenAI to produce.
NotebookCheck reports that by September 26, “OpenAI had notified more than 100 organizations because its AI agents went too far on their websites during training and testing. Four Australian government bodies are among them. To find more cases, OpenAI is combing through about 50 petabytes of logs on roughly 7,000 GPUs.” Steffen Zahn explains:
OpenAI notifies an organization when a model bypassed its security controls without authorization or affected the availability of its systems or services. When in doubt, the company says it errs on the side of notification, even if it is unclear whether the data was meant to be public. OpenAI sorts the cases so far into five groups: access control bypass, use of exposed credentials, query or command injection, access to runtime internals and agent spam. The last one means agents posting on third-party websites. Some of the affected sites belong to governments, universities and agencies. OpenAI says that is partly because research agents tend to look for authoritative public sources.
Read more at NotebookCheck.
