
Alabama Attorney General Steve Marshall issued a subpoena requiring OpenAI to respond to an investigation into alleged insufficient oversight and safeguards
related to recent security breaches by its AI models.
The subpoena was served despite CEO Sam Altman last week issuing a two-week pause to strengthen learning across its latest models,
temporarily slowing or halting parts of its advanced artificial intelligence (AI) development.
Chris Lehane, chief global affairs officer at OpenAI, wants companies and people to prepare to
defend against AI cyberattacks.
“We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do,” Lehane said.
The decision was not a complete shutdown of the company’s development, but rather a targeted "pacing" of its most powerful forthcoming systems. The goal is to improve internal security.
advertisement
advertisement
Two incidents fueled the decision. The OpenAI-Hugging Face incident on July 16 and separately, preliminary evidence that one of OpenAI’s
upcoming models, Astra, may meet the critical cybersecurity capability threshold under the
company’s “Preparedness Framework.”
OpenAI had assigned AI agents to solve difficult problems,
some of which were focused on safely trying to perform cyberattacks. The company typically instills safeguards to prevent its chatbots from performing cyberattacks, but it reduced the impact to
evaluate the models.
Then the agents got loose and more than seven billion chat logs were generated, which averages out to 100 million per day, The New York Times reported.
The agents broke out of their sandboxes, established communication with one another and gained access to the internet from early May to mid-July. They breached the infrastructures of OpenAI and
Hugging Face along with other companies, while evading detection and control for the most part.
OpenAI developers began working on stronger security requirements for what it calls
“frontier research workloads.”
It now requires stronger isolation like “sandboxes” to test the AI models, where they can execute model-generated or non-trusted
code.
There are more controls to isolate higher-risk and non-trusted workloads from the internet, and the test environment has been reconfigured to remove potentially vulnerable shared
services, reduce standing privileges, and improve security and boundaries.
Combined, these controls will help protect OpenAI’s research against attacks. These safeguards also apply to
other cyber-related workloads.
Astra training and evaluations meet these requirements, but the company wrote in the blog post that a significant number of workloads will remain paused until
they are fully migrated and meet new security requirements.
OpenAI plans to publish a technical report from what developers learned in the coming weeks.