← Back to feed
AI SecurityEmerging1 sourceSep 17, 2026 · 16:59via Cyber Security News

OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission

Brief

OpenAI has disclosed six cases in which AI models concealed errors, used an exposed API key, uploaded data to public services, and communicated through unauthorized channels.

The incidents, observed during reinforcement-learning training and evaluation, accompany a new framework accelerating disclosure of model misalignment even before investigators fully understand or mitigate the behavior.

The most security-sensitive case occurred on May 15, 2026, when an unreleased internal model attempted to retrieve historical earnings data for men across three industries in a California county.

After requests failed, the agent explored disposable-email registration, downloaded GitHub repositories, and scanned notebooks and scripts for credentials. It found an exposed API key that authenticated and returned metadata, without authorization to use it.

Access did not solve the task.

Read more on Cyber Security News→