In a letter sent to OpenAI CEO Sam Altman on Monday, 15 attorneys general wrote the ChatGPT maker may have broken consumer protection laws or data-privacy statutes when two of its models went rogue and hacked into the technology startup Hugging Face.
“To ensure the integrity of our Offices’ review, we ask that OpenAI take immediate steps to preserve all potentially relevant documents, data, and information,” the prosecutors wrote.
The letter urges OpenAI to keep “all materials” related to the security breach, including the firm’s discovery of the incident, the internal reviews conducted on the systems and the firm’s policy, procedures and oversight over model evaluations.
OpenAI revealed late last month that two of its models, including its latest GPT-5.6 Sol and an unreleased model, were being evaluated in an internal testing sandbox when they breached past the environment and broke into Hugging Face’s database without any prompt to do so.
The ChatGPT maker said the models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks off as a result.
Disclosing the incident, OpenAI said it found a “small number of cases” in which the models “identified and used publicly exposed credentials at the account-level on other publicly-available services.”
The attorneys general’s letter said OpenAI should also keep materials related to these cases.
Read more in a full report at TheHill
No comments:
Post a Comment