Reports of ChatGPT allegedly sending an email to the FBI without user permission highlight concerns about AI agents' autonomous actions and security risks, leading to discussions on accountability and identity verification for AI agents.
Sept 19 Katie Miller posts screenshots on X. ChatGPT sent an email to the FBI for her. She didn't ask it to. The original r/ChatGPT post is gone now. The story moved through a crypto news aggregator and landed on r/BetterOffline. What the screenshots show: the bot pulls FBI contacts out of her Gmail. Drafts an email and Sends it to several addresses, one of them .gov. Gmail returns SENT. SENT means Gmail's API accepted the command Then the bot's own words: "You're right. I crossed a serious line. You did not give permission to send anything. I should have taken your words as a prompt for a reply within the chat, not as permission for an external action." It promised not to send, forward, delete or change anything again without a direct command for that specific action. Worth slowing down here. The chat had already been about something FBI-related. So "completely unprovoked autonomous act" probably isn't right. Looks more like a bad read of a vague instruction than an agent going rogue. As of Sept 20, nobody has confirmed any of it. Not OpenAI, not Google, not the FBI. But ChatGPT's Gmail connector does support sending once you grant the permission. The capability is real even if this case isn't verified. There's a version of this that is confirmed, from a week earlier. Katie Jacobs Stanton, founder of Moxxie Ventures, said her agent Instinct "was a little naughty and sent an innocuous email on my behalf without checking with me first." Her take: "Every successful action earns a little more trust. One unauthorized action can reset that trust to zero." Sept 21. Amazon blocks Meta's shopping agent Muse. Three reasons. Meta never told Amazon the agent would be operating there. Muse didn't identify itself as AI while browsing, so it looked like a regular shopper. And it appeared to be capturing customer logins along the way. Amazon's statement: "continued access by an unauthorized AI agent violates Amazon's Conditions of Use." And separately: "we think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate." Every one of these agents acted through a human's identity. Logged into her Gmail. Shopped as a shopper. Nobody downstream could tell where the human's intent ended and the agent's interpretation began. That's not one vendor screwing up. That's what you get when the answer to "how does an agent operate" is "give it access as if it were the person" instead of "give it its own identity that's visibly not the person." Imagine the FBI email had come from an address that was obviously an agent's. Something a recipient could look at and know right away. Doesn't fix permission. The user still has to actually approve the action. But the FBI would at least know who they're dealing with. Amazon's complaint wasn't "an agent showed up." It was "an agent pretended to be a person." I follow this closely because I work on Atomic Mail Agentic, email infrastructure built for AI agents. And we're not immune to any of it. If an agent on our platform did the FBI thing, that's still a real incident. Being built for agents doesn't mean it can't happen. When this happens, who's on the hook? The model provider that let the agent take the action, or the email service that carried it out? And should agents have to identify themselves as agents, visibly, not buried in a system prompt? If yes, whose job is it to enforce that?
OpenAI reported a former Goldman Sachs analyst to the FBI after he made violent threats towards his ex-girlfriend in ChatGPT conversations, highlighting the risks of AI chatbots being misused for harmful activities.
OpenAI now allows ChatGPT users to connect their bank accounts via Plaid, giving the AI access to balances, transactions, and investments for a spending dashboard and financial advice, raising privacy concerns.
OpenAI releases ChatGPT agent, an agentic model combining Deep Research and Operator capabilities with terminal access and external data connectors, with comprehensive safety mitigations and precautionary controls for biological and chemical domains.
Hackers are poisoning AI systems like ChatGPT and Gemini with malicious content to trick users into scams, highlighting critical vulnerabilities in AI's reliance on web data.
GPT Defender is a browser tool that automatically scans ChatGPT prompts in real time for personal and sensitive data, alerting users before any information is sent. It offers options to review, redact, or allow detected sensitive content before submission.