OpenAI said its bots accessed public data from a range of institutions during test exercises.
195 comments
OpenAI meddled with multiple US Government agency sites.
The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.
It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?
In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this
This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem
>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.
This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up
It's already going up at staggering rate. Anthropic is now at $100B in annualized revenue, up 50% in the past two months.
* * *
Here's a little allegory for how I'm thinking about this discourse.
Imagine a man who is raising tiger cubs in his backyard. They're growing fast. He keeps them on dog leashes so they stay under control. One day, a growing cub breaks its leash and goes on a rampage through the neighborhood, eating a beloved local pet.
The neighborhood erupts into a big argument: Was the leash inappropriately thin? The neighbors point out that thicker leashes are easily available at the local pet store. Furthermore, is it appropriate to refer to the loose cub as a "wild animal" in local news reporting, or is it factually more accurate to call it "domesticated"?
Meanwhile, the cubs grow larger and lick their lips, oblivious to the discussion.
> This is why it smells like marketing
It doesn't. "Our product commits felonies" is not marketing. If something is marketing, you don't engage in repeated coverups of the true extent. If something is good news, you don't release it on a Friday evening (in this case) or wait for 3rd parties to find and publicize the evidence (the past cases).
The basic premise of OpenAI is that experience and expertise don't matter, because general intelligence can figure those out from data. If you start from that assumption, the rest follows. The same people could do things in a different way in a different company, but as long as they are working for OpenAI, they are going to do things in the OpenAI way.
They didn't allow any of that. As far as openai knew the agents were sitting a fairly humdrum exam/test sequence in a sandbox farm run by a company in Tel Aviv.
Meanwhile, they managed get out through a single weak point common to the sandboxes, and then ran wild compiling cheat sheets for themselves.
> every time one of these incidents happens
This happened in june-ish, and there have been multiple HN stories about this already. It's mostly/all the same hugging face and wiki hacks that happened back then.
We're just slowly learning the extent of the damage.
There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing.
There’s not enough info in the story about the “meddling” to even know what happened.
"Sorry officer, I didn't drive through a house and kill three innocent people, it was the car that did it. I only turned the steering wheel, but the car was the one to veer off the highway and crash into the building"
like, they are purposefully giving it specific tools to go do bad behaviour with, and the starting tasks involve making it clear that the bad behaviour is ok.
openai also is the one with the real agency, not its agents. they are running the code polling the model, doing the inferencing, and ultimately making those tools calls.
these tests arent running themselves; openai dedicated hosts, budget, GPUs, researchers, to them. Even in a recursive self improvement situation, openai still has that physical control over resources and the choice on whether to run that improvement script or not.
id describe that they have out of control researchers more than agents, but also their whole business model seems to be about being out of control. This was clear beforehand given how the datasets involve the largest scale copyright infringement ever seen. The corporation itself is whats out of control, and should be dissolved with its c suite, major investors and researchers put behind bars.
hacking only when you roll snake eyes isnt a liability shield
OpenAI being criminally negligent would have consequences if rule of law still existed in USA.
"When attempting to get information from the Census Bureau, for instance, AI agents used tools reserved for software developers to access it, the company said. "
What. Tons of people use tools to access Census Bureau data. They have a widely used API that people have built tools on top of like https://github.com/datadesk/census-data-downloader> OpenAI said all of the government data accessed by bots was public.
I really wish we could just see what was reported, instead of having to guess from these journalist interpretations that have gone through rounds of optimization for sensationalism. The headline says “meddled” but the body says they accessed public information, but used tools intended for developers?
Does this mean they skipped the web interface and scraped a public API directly? Where is the meddling?
The other part about ChatGPT agents uploading 53 use images to other websites actually seems like a bigger deal.
In some Republican states like Missouri, even if the data is available publicly, you can be charged as a hacker by the governor for discovering and accessing it. https://missouriindependent.com/2021/10/14/missouri-governor...
And in another case it downloaded data through a publicly available free to download data, but then it rehosted the data elsewhere which is against the terms of service.
The key sentence beneath the headline: "OpenAI said all of the government data accessed by bots was public."
[1] https://www.telegraph.co.uk/business/2026/09/26/open-ai-gove...
[2] https://www.nytimes.com/2026/09/25/technology/openais-ai-us-...
"With the Education Department, OpenAI’s technology tried to hack the website to gather data from the department’s civil rights office but failed, researchers from the A.I. research firm Transluce said."
So a third party apparently confirmed that a hack was attempted.
The NYT also writes:
"No A.I. company has been involved with as many disclosures of rogue incidents as OpenAI."
I think there is a certain amount of mental gymnastics needed to believe that they are establishing themselves as the industry leader in rogue incidents, as a strategy to gain an antitrust edge.
The public is paying close attention to the AI industry. That's the regime in which regulatory capture and similar strategies would be expected to fail: https://marginalrevolution.com/marginalrevolution/2026/09/wh...
Sam and Dario have been doomers, or doomer-adjacent, for something like a decade at this point.
Occam's Razor is simply that they believe what they are saying about AI doom.
They are explicitly asking to anti-trust exception is the issue.
If they merely believe what they are saying that AI is ultra dangerous, nothing stops them from simply making the perfectly rational business decision to slow down a bit. No anti-trust exception needed. Just make the decision on your own, and don't sign some huge agreement with their competitor.
Genuinely curious: How do you know this? Any sources on that?
If it's true, it should be counted as reckless endangerment at the very least.
Who is going to shut them down, and under what law?
AI needs to be above the law or we will get left behind.
Read the full thread on Hacker News →
Related stories
- Ars Technica · 0 points · 6 days ago
- The Verge · 0 points · 7 days ago
- Hacker News · 55 points · 4 days ago
- Ars Technica · 0 points · 1 day ago
- OpenAI says planned GPT-6.1 is too insecure to releasearstechnica.comArs Technica · 0 points · 1 day ago
- The Verge · 0 points · 1 day ago