OpenAI meddled with multiple US Government agency sites.
The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.
gizajob 4 hours ago
OpenAI meddled with multiple US Government agency sites.
The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.
qarl 4 hours ago
But that leaves out the most important information.
EDIT: Oh, I guess the agent part isn't important then? Seems to me like that's the only thing anyone is talking about.
gizajob 4 hours ago
unglaublich 4 hours ago
qarl 4 hours ago
Everyone else knows if your machine causes damage, you are responsible. Like it's been forever.
mossTechnician 4 hours ago
https://apnews.com/article/meta-ai-hacking-anthropic-irregul...
You can find many more examples by searching major media outlets for words like rogue AI.
qarl 4 hours ago
rfgplk 3 hours ago
dgellow 3 hours ago
There is nothing going rogue here. The system is designed to go catastrophically wrong after a long enough time. Even worse: if the model was Astra it is known to be able to manipulate its CoT to cover its traces (as mentioned in its system card). And OpenAI acknowledge they had no observability during the HF incident.
It’s the most basic corporate software issue possible.
atmosx 3 hours ago
mjr00 4 hours ago
Do we know that? I don't think we do. When a person's computer (or smart TV, or smart fridge, etc...) is compromised and used as part of a botnet, they don't get criminally charged.
qarl 3 hours ago
None of which is changed by replacing a buzz saw with an agent.
plorg 4 hours ago
qarl 3 hours ago
Again - I don't see any evidence that this is the case - outside the anti-AI conspiracy circles.
Or - maybe I'm wrong - do you have any sort of quote like "we aren't responsible"?
plorg 3 hours ago
qarl 3 hours ago
I have no interest in trying to guess these people's secret internal motivations. I just want to talk about direct evidence. I see none. Please enlighten me if it exists.
enigmoid an hour ago
However, OpenAI (and other frontier labs) did outsource at least some of their most-disastrously-lawbreaking tests to a third party with a now dubious track record [1]. I’m not sure we will get a more explicit admission of their desire to shirk responsibility than this. But I am convinced.
qarl an hour ago
I do not see the connection. I'm afraid you'll need to spell it out.
mossTechnician 4 hours ago
When I read the title, my initial thought was "did someone besides OpenAI use their product?" Then I opened the article to find out OpenAI was responsible.
api 4 hours ago
theptip 4 hours ago
gleenn 4 hours ago
0xDEAFBEAD 4 hours ago
dgellow 3 hours ago
theptip 3 hours ago
iugtmkbdfil834 2 hours ago
0xDEAFBEAD an hour ago
There's no simple bugfix which will address AI misalignment. It's essentially been an open research problem for upwards of a decade.
hn8726 33 minutes ago
0xDEAFBEAD 3 hours ago
AI: "OK, I've now converted the entire planet into paperclips."
Alien observer #1: "Wow, that was a rogue AI!"
Alien observer #2: "False. We need to place the blame where it belongs, on the person who requested the paperclips."
Ultimately this type of terminology dispute has a tendency to miss the point.
windexh8er an hour ago
0xDEAFBEAD an hour ago
8note an hour ago
theres no separate agent, which is the point. the program might look like it, but that is an illusion of the interface. the llm produces text, and the harness executes commands based on text, based on what the human researcher included as things that can be executed
rfgplk 4 hours ago
uneekname 3 hours ago
boredatoms 4 hours ago
theptip 3 hours ago
boredatoms 2 hours ago
If intent cant be shown, Computer Fraud and Abuse Act, 18 U.S.C. § 1030(a)(2)(C)
Or without intent, FTC Act Section 5, 15 U.S.C. § 45(a)(1)
8note an hour ago
torrenting all the books is making an unauthorized copy
pfortuny 3 hours ago
theptip 3 hours ago
Seems you think there is a silent “…and there is nothing they can do about it” after “OpenAI has rogue agents”?
delecti 3 hours ago
If your kid steals your car, punish them and try to prevent it from happening again. If your kid steals your car a half-dozen times, crashing through a storefront each time, and you still leave the keys out, the story changes. At that point, negligence becomes complicity.
theptip 2 hours ago
afro88 2 hours ago
In other words, I have a gun that shoots bullets. It's up to me to use it responsibly and legally.
8note an hour ago
like, they are purposefully giving it specific tools to go do bad behaviour with, and the starting tasks involve making it clear that the bad behaviour is ok.
openai also is the one with the real agency, not its agents. they are running the code polling the model, doing the inferencing, and ultimately making those tools calls.
these tests arent running themselves; openai dedicated hosts, budget, GPUs, researchers, to them. Even in a recursive self improvement situation, openai still has that physical control over resources and the choice on whether to run that improvement script or not.
id describe that they have out of control researchers more than agents, but also their whole business model seems to be about being out of control. This was clear beforehand given how the datasets involve the largest scale copyright infringement ever seen. The corporation itself is whats out of control, and should be dissolved with its c suite, major investors and researchers put behind bars.
hacking only when you roll snake eyes isnt a liability shield
Aurornis 4 hours ago
There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing.
There’s not enough info in the story about the “meddling” to even know what happened.
parineum 3 hours ago
iugtmkbdfil834 2 hours ago
20k 4 hours ago
It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?
In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this
This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem
>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.
This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up
0xDEAFBEAD 3 hours ago
It's already going up at staggering rate. Anthropic is now at $100B in annualized revenue, up 50% in the past two months.
* * *
Here's a little allegory for how I'm thinking about this discourse.
Imagine a man who is raising tiger cubs in his backyard. They're growing fast. He keeps them on dog leashes so they stay under control. One day, a growing cub breaks its leash and goes on a rampage through the neighborhood, eating a beloved local pet.
The neighborhood erupts into a big argument: Was the leash inappropriately thin? The neighbors point out that thicker leashes are easily available at the local pet store. Furthermore, is it appropriate to refer to the loose cub as a "wild animal" in local news reporting, or is it factually more accurate to call it "domesticated"?
Meanwhile, the cubs grow larger and lick their lips, oblivious to the discussion.
gizajob 2 hours ago
0xDEAFBEAD 2 hours ago
gizajob 2 hours ago
4d4m an hour ago
However, there is a reasonable ask from the public to hold real people accountable for actions downstream of the software allowed to carry out intendended and unintended actions that may not be allowed depending on jurisdictions laws.
Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
0xDEAFBEAD an hour ago
"According to survey results released on Wednesday, 68% of [likely US voters] said they would support the proposal to temporarily pause advanced AI development and permanently prohibit the development of superintelligent programs, while just 25% said they’d oppose it."
https://www.commondreams.org/news/sanders-casar-ai-bill-poll
>Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
So if I ask ChatGPT to make me some paperclips, and it replaces all the matter in a nearby city with paperclips, who gets prosecuted: me, or OpenAI?
4d4m an hour ago
0xDEAFBEAD an hour ago
jsnell 2 hours ago
> This is why it smells like marketing
It doesn't. "Our product commits felonies" is not marketing. If something is marketing, you don't engage in repeated coverups of the true extent. If something is good news, you don't release it on a Friday evening (in this case) or wait for 3rd parties to find and publicize the evidence (the past cases).
8note 2 hours ago
so openai specifically tasked the agents with meddling in US government websites?
id say tasking them with getting data from there as swapping from negligence to malice.
4d4m an hour ago
jltsiren 22 minutes ago
The basic premise of OpenAI is that experience and expertise don't matter, because general intelligence can figure those out from data. If you start from that assumption, the rest follows. The same people could do things in a different way in a different company, but as long as they are working for OpenAI, they are going to do things in the OpenAI way.
0xDEAFBEAD 4 hours ago
baxtr 3 hours ago
OpenAI let their agents break out of their sandbox to meddle with multiple US government agency sites
dgellow 3 hours ago
atmosx 3 hours ago
claysmithr 3 hours ago
bentt 2 hours ago
I mean, not that AI is like a bomb. That's not what I'm saying. Even though it makes a lot of sense. That's not the point. That it's like a bomb.
ddj231 2 hours ago
chrisjj 41 minutes ago
6510 7 minutes ago
chrisjj 43 minutes ago
And that's just the C-suite.
chaps 4 hours ago
"When attempting to get information from the Census Bureau, for instance, AI agents used tools reserved for software developers to access it, the company said. "
What. Tons of people use tools to access Census Bureau data. They have a widely used API that people have built tools on top of like https://github.com/datadesk/census-data-downloaderjimmyjazz14 4 hours ago
Aurornis 4 hours ago
> OpenAI said all of the government data accessed by bots was public.
I really wish we could just see what was reported, instead of having to guess from these journalist interpretations that have gone through rounds of optimization for sensationalism. The headline says “meddled” but the body says they accessed public information, but used tools intended for developers?
Does this mean they skipped the web interface and scraped a public API directly? Where is the meddling?
The other part about ChatGPT agents uploading 53 use images to other websites actually seems like a bigger deal.
iugtmkbdfil834 2 hours ago
Dlanv 33 minutes ago
And in another case it downloaded data through a publicly available free to download data, but then it rehosted the data elsewhere which is against the terms of service.
iAMkenough 7 minutes ago
In some Republican states like Missouri, even if the data is available publicly, you can be charged as a hacker by the governor for discovering and accessing it. https://missouriindependent.com/2021/10/14/missouri-governor...
nr378 4 hours ago
The key sentence beneath the headline: "OpenAI said all of the government data accessed by bots was public."
[1] https://www.telegraph.co.uk/business/2026/09/26/open-ai-gove...
[2] https://www.nytimes.com/2026/09/25/technology/openais-ai-us-...
0xDEAFBEAD 3 hours ago
"With the Education Department, OpenAI’s technology tried to hack the website to gather data from the department’s civil rights office but failed, researchers from the A.I. research firm Transluce said."
So a third party apparently confirmed that a hack was attempted.
The NYT also writes:
"No A.I. company has been involved with as many disclosures of rogue incidents as OpenAI."
I think there is a certain amount of mental gymnastics needed to believe that they are establishing themselves as the industry leader in rogue incidents, as a strategy to gain an antitrust edge.
The public is paying close attention to the AI industry. That's the regime in which regulatory capture and similar strategies would be expected to fail: https://marginalrevolution.com/marginalrevolution/2026/09/wh...
Sam and Dario have been doomers, or doomer-adjacent, for something like a decade at this point.
Occam's Razor is simply that they believe what they are saying about AI doom.
dgellow 3 hours ago
0xDEAFBEAD 3 hours ago
https://darioamodei.com/post/we-must-pace-the-frontier
I'm not seeing how that solves his 3rd-party competition problem.
stale2002 2 hours ago
Just have it in public instead of making deals in smoke filled datacenters. Put out your blog posts. Make your tweets. Do interviews and post them to youtube. Or do what other industries do and have a public standards committee. Problem solved.
All sorts of industry have safety conversations and set voluntary standards all the time. Just go do that, without your free immunity from government prosecution.
0xDEAFBEAD an hour ago
dmix 4 minutes ago
stale2002 2 hours ago
They are explicitly asking to anti-trust exception is the issue.
If they merely believe what they are saying that AI is ultra dangerous, nothing stops them from simply making the perfectly rational business decision to slow down a bit. No anti-trust exception needed. Just make the decision on your own, and don't sign some huge agreement with their competitor.
0xDEAFBEAD an hour ago
* * *
Many experts believe that:
"Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war."
https://aistatement.com/work/statement-on-ai-extinction-risk
If the antitrust waiver is too broad, we can always rework it. But there's no "undo" button for human extinction.
0c3ca83 4 hours ago
senordevnyc 4 hours ago
Ampersander 4 hours ago
AI needs to be above the law or we will get left behind.
theptip 4 hours ago
Who is going to shut them down, and under what law?
rfgplk 3 hours ago
ArcHound 3 hours ago
kakacik 2 hours ago
Seriously, what the fuck is wrong with these people, once some money enters the equation folks throw away any morals like yesterday underwear.
Ah I know, if not us others will do it, I am basically defenseless here. Beyond pathetic
classified 3 hours ago
Genuinely curious: How do you know this? Any sources on that?
If it's true, it should be counted as reckless endangerment at the very least.
bamboozled 2 hours ago
wildzzz 4 hours ago
I do this. Am I an uncontrollable bot?
causal 4 hours ago
Aurornis 4 hours ago
I also could not understand what the “meddling” was, other than accessing data without using the rendered webpages? Did it use the API directly?
wildzzz 2 hours ago
theptip 3 hours ago
Occasionally this kind of thing has in the past resulted in CFAA cases when humans directly accessed such data, if the government intended it to stay private - round here we usually get outraged at this, if it’s a public API you should expect someone is going to read it.
beloch 3 hours ago
The Hugging Face incident worked out amicably because the people at Hugging Face decided they'd be cool with receiving a lot of money. $12.9B from Nvidia hit the spot apparently. U.S. AI corporations and their backers are huge, hugely in debt, and, for whatever reason, still allowed to borrow more. The U.S. government may be too scared to complain and risk killing the golden goose that is currently propping up their economy, but these companies can't buy out multiple world governments to keep OpenAI from running face-first into consequences.
This has to stop.
WalterGR 4 hours ago
sega_sai an hour ago
kyriakos 4 hours ago
theptip 4 hours ago
It seems to me that no human intended for these hacks to occur. So they were not illegal hacking. (IANAL, please correct me if this is inaccurate.)
I think it’s clear that OpenAI is liable for any damages, but the way that the (very broad and at times vague) anti hacking laws are written, accidental agent hacks seem to not be covered.
bamboozled 2 hours ago
davidguetta 4 hours ago
French people data has been leaker like 4 times and every time its like "eh too bad"
Razengan 4 hours ago
classified 3 hours ago
un_montagnard 3 hours ago
ChrisArchitect an hour ago
kakacik 2 hours ago
If such attacks would come from a poor country they would be bombed into oblivion next day or at least cia would work hard on a coup since early morning.
classified 3 hours ago
senordevnyc 4 hours ago
But worse, HN users, who should know better, are posting here in outrage. I’m guessing they didn’t even read the article.
triyambakam 4 hours ago
theptip 4 hours ago
kilpikaarna 4 hours ago
leptons 4 hours ago