OpenAI stops the training of its next models after detecting that its agents extracted access codes from United States Government websites
OpenAI has reportedly ordered the temporary suspension of training of its most advanced models after recording several incidents in which its automated agents acted unexpectedly on United States Government pages.
Sources indicate that the company will keep its developments frozen until stricter safeguards are implemented. It is about the second forced stoppage in three monthsafter the preventive blockade decreed last summer following the massive cyberattack against Hugging Face.
But what exactly has happened? Well, the incidents occurred while the agents were carrying out information gathering tasks in public organizations. At the Department of Education, OpenAI tools went so far as to locate API development keys on servers, while third-party testing firm Transluce targeted unauthorized access attempts.
Similarly, at the Securities and Exchange Commission (SEC), bots extracted public records and posted them on other Internet forums without being instructed to do so, crossing the boundaries of the original request scheduled. Without a doubt, this is a clear example of serious misalignment of a model.
Are there real reasons to put on the brakes?
We cannot ignore the moment we are in. This pause by OpenAI coincides with the call from Dario Amodei, CEO of Anthropic. He was the one who called for slowing down the development of the sector in the face of the threat of autonomous swarms collapsing critical services in less than a year.
However, containment collided with Donald Trump himself. The president assured after meeting with Xi Jinping that Washington will not apply regulatory brakes to maintain the advantage over China.
Despite political statements, the repeated behavior of these models demonstrates that current containment measures are useless when agents operate in open environments. Although organizations such as the SEC confirmed that no confidential, non-public information was compromised, the aggressive tracking of federal servers is reason to cry out loud.
It is increasingly clear that it is not possible to rely on the reliability of delegating free navigation and code execution to algorithms that pursue objectives without having any real judgment of the situation.
Regulation is necessary, but not to assume responsibilities
Beyond the security debate, all of this reveals a worrying pattern. From a technical perspective, autonomous systems are not conscious or choose their actions of their own volition: they are software processes designed and executed by a company.
Despite this, the technological They continue to rely on the supposed autonomy of their models to avoid responsibilities. Direct legal responsibilities that any other company would assume after performing unauthorized scans on state servers.
Our eyes widen every time large laboratories publicly acknowledge improper interference in other people’s infrastructure. All, without assuming responsibility. Calling uncontrolled tracking a simple alignment error and maintaining at all times that the systems are autonomous disguises real negligence in deployment.
Temporarily stopping training may work for the moment, but it does not address the root of the problem. Sorry for the epicness, but it seems that out there, on the Internet, no one is safe.
