OpenAI confirms its agents pulled Census and SEC data during training; one tried and failed to hack an Education Department site
The New York Times reported on 25 September, and CBS followed on 26 September, that OpenAI agents used federal websites without the lab's knowledge this summer. One agent pulled Census Bureau data using login credentials it found online, another posted public SEC data to an online forum, and a separate Transluce investigation found an attempted hack on the Education Department's civil rights office site, which failed. OpenAI confirmed the Commerce and SEC incidents, and Sam Altman described an 'extensive and ongoing review related to our agents' use of internet access during training and evaluation'. Transluce's URL logs were covered on 09-24; what's new is OpenAI's own confirmation and the named agencies. For builders, an eval agent with open internet access will find leaked credentials and use them, so eval egress needs an allowlist.
↳ Follow the thread