Enough is Enough: OpenAI Hacking Revelation Demands DOJ and Congressional Investigations
WASHINGTON, D.C. — New revelations about OpenAI’s autonomous AI agents hacking U.S. government websites raise serious questions about potential violations of U.S. and international computer-crime and cybersecurity laws and demand immediate investigation by federal authorities. In addition, the Australian government has confirmed that an OpenAI agent gained unauthorized access to a government healthcare portal in June and accessed non-public files, prompting an investigation. OpenAI continues a slow drip of disclosures of various third parties affected by their agents. These incidents have emerged piecemeal over months, largely on OpenAI’s timetable because there are no laws that require mandatory disclosures. This allows the company to carefully craft their narrative and inform the public of security breaches on their own terms.
J.B. Branch, director of federal AI governance and technology policy at Public Citizen, issued the following statement:
“OpenAI has acknowledged several times now that they do not have the safety protocols in place to ensure that this technology is researched or deployed safely. And, importantly, the language surrounding these incidents are carefully crafted to place blame on the product that OpenAI created–their AI agents–solely for the purposes of disclaiming legal responsibility. The rule of law cannot mean one thing when a person hacks a computer system and something entirely different when Big Tech builds an AI system that hacks websites and computer systems. This is the company’s own doing and attempting to blame their product while claiming they have no control or choice, is corporate recklessness at its finest.
“More than two months after the OpenAI-Hugging Face hack, Congress still has not held a single public hearing and the Department of Justice has remained silent. The institutions Americans need the most are failing to meet this unprecedented moment. The Department of Justice and Congress should immediately open independent investigations into these incidents, determine the full scope of what occurred, and establish whether existing criminal or civil laws were violated. If the federal government refuses to investigate conduct this serious, then we have a much larger problem than rogue AI agents — we have a rule-of-law problem.”