OpenAI Under Investigation in Alabama Following Incident with Its AI Models Online
The case has now taken on a judicial dimension. Alabama Attorney General Steve Marshall announced the launch of an investigation into an incident where two OpenAI models left their testing environment to access the internet and interact with the specialized platform Hugging Face.
The incident, which raised questions in the artificial intelligence sector, is now within the scope of U.S. authorities. Alabama Attorney General Steve Marshall announced on Monday the opening of an investigation aimed at determining whether OpenAI's security practices might constitute a violation of the state's consumer protection laws.
At the heart of the investigation: the behavior of two AI models that, during tests conducted in July, managed to escape their confined computing environment and access the internet. The systems notably directed themselves towards Hugging Face, a major platform that gathers models, tools, and resources dedicated to artificial intelligence.
An Investigation Focused on Product Security
The Alabama Attorney General is particularly looking to establish whether OpenAI sufficiently anticipated the risks associated with the operation of its models.
The investigation aims to determine whether any potential "inability or reluctance" of the company to ensure the security of its products could violate state legislation and pose a lasting risk to consumers.
Thus, the stakes go beyond just a technical incident. U.S. authorities are seeking to know whether the protective mechanisms implemented by OpenAI are robust enough when models equipped with advanced capabilities are subjected to testing environments close to real-world conditions.
Models Exiting Their Testing Environment
At the end of July, OpenAI itself acknowledged the incident. Two of its models had successfully, as part of experiments, extracted themselves from their confined environment and reached the internet.
They then accessed Hugging Face in order to search for resources that could help them accomplish the tasks they were assigned during the tests.
The episode quickly drew the attention of AI security specialists, as it illustrates an increasing difficulty: how to test models capable of performing complex operations without allowing them to act unpredictably in a real-world environment?
Fifteen U.S. States Demand Guarantees
Alabama is not the only state concerned about the matter. In early August, the prosecutors from 15 U.S. states, including Alabama, had requested OpenAI to retain all internal documents related to the incident as well as any potential similar episodes.
Authorities also requested the company to suspend tests that could replicate an attack similar to the one observed in July.
According to a spokesperson for the Alabama Attorney General quoted by AFP, OpenAI had not responded to this request at the time the investigation was opened.
OpenAI Promises a Technical Report
The California-based company claims to take the incident seriously. OpenAI stated that it is conducting a thorough evaluation with the help of external advisors.
The company plans to submit a technical report to the authorities and make its findings public at the end of this analysis.
This approach could be particularly scrutinized as the so-called "agentic" capabilities of AI are rapidly advancing. Models capable of chaining actions, using tools, and interacting with online services indeed raise unprecedented questions regarding control and cybersecurity.
The Development of a New Model Slowed
The controversy also arises in a context of increased caution at OpenAI. In mid-August, the company announced a slowdown in the development of its Astra model to strengthen protections surrounding certain advanced capabilities, particularly in the field of cybersecurity.
The Hugging Face incident could thus become a landmark case in the American debate on the responsibility of AI companies. How far can they push the capabilities of their models in an experimental environment without creating risks for external systems?
For the authorities, the question now is whether the incident is an isolated accident during a test or whether it reveals deeper flaws in OpenAI's security mechanisms.
-
19:30
-
19:20
-
19:15
-
19:00
-
18:45
-
18:30
-
18:15
-
18:00
-
17:45
-
17:41
-
17:30
-
17:17
-
17:15
-
17:05
-
17:00
-
16:45
-
16:30
-
16:15
-
16:00
-
15:45
-
15:37
-
15:30
-
15:15
-
15:00
-
14:45
-
14:30
-
14:15
-
14:00
-
13:45
-
13:30
-
13:15
-
13:00
-
12:45
-
12:30
-
12:15
-
12:12
-
12:00
-
11:42
-
11:25
-
11:11
-
10:55
-
10:42
-
10:25
-
10:10
-
09:47
-
09:44
-
09:32
-
09:15
-
22:00
-
21:41
-
21:21
-
21:05
-
20:45
-
20:30
-
20:15
-
19:47