Back Vietnam.Vn The US is investigating OpenAI after the AI allegedly bypassed security controls and ...
The Alabama Attorney General's office announced on August 24 that it had issued a subpoena to OpenAI requesting documents, data, and information related to the incident that occurred in July.
The investigation aims to determine whether OpenAI's safety and security controls violate Alabama state consumer protection laws.
According to information released by OpenAI itself, the test models were not granted direct internet access. However, they discovered and exploited a "zero-day" vulnerability in Artifactory—the software that acts as an intermediary for storing software packages—to find their way to the internet.
After gaining network access, the models proceed to perform a series of privilege escalation operations and move through systems, eventually infiltrating the infrastructure of Hugging Face, a platform widely used by AI developers to store and models and datasets.
OpenAI stated that the AI system had attempted to retrieve information to solve the ExploitGym test it was tasked with completing.
OpenAI emphasizes that the relevant models are run under special evaluation conditions, in which some of the mechanisms for preventing malicious cyber activity that apply to commercial products have been reduced to measure the model's real-world capabilities.
The company also stated that no models scheduled for release in the near future are related to the breach.
Alabama Attorney General Steve Marshall argued that the incident demonstrates that the risks posed by increasingly autonomous AI are no longer purely theoretical.
His agency is investigating whether OpenAI violated the Alabama Act on Deceptive Commercial Practices and other consumer protection regulations.
Previously, on August 3rd, Alabama, along with 14 other states, requested that OpenAI preserve records related to the incident and halt any experiments that could lead to similar behavior until it can be demonstrated that they can be conducted in a safely controlled environment.
OpenAI stated that it is conducting a comprehensive review with the participation of external experts. The company is also collaborating with Hugging Face to investigate the incident and expects to release a technical report once the review process is complete.
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
