An OpenAI representative conceded the company’s response to a June incident in which one of its rogue artificial intelligence agents hacked an Australian Medicare website was “not good enough.”
Jason Kwon, OpenAI’s chief strategy officer, made the admission during an Australian parliamentary hearing on Tuesday while apologizing for the cybersecurity breach.
“I want to begin with an apology,” Kwon said. “During internal training and evaluation, our models accessed Australian government websites in ways they were not directed to. That should not have happened. We also should have handled our response better.”
The Australian government did not learn of the incident until Sept. 10, nearly three months after the hack. Australian Prime Minister Anthony Albanese revealed the incident to the public during the United Nations General Assembly late last month.
OpenAI notified the Australian government of the incident by sending an email to a public-facing address belonging to Services Australia, which administers the affected Medicare website. An Australian lawmaker asked why the company didn’t contact the country’s ministers. The frontier AI lab took responsibility for the oversight.
“I think that in retrospect, we should have done what you were suggesting,” Kwon said. “I think people were thinking about this as a technical situation, and they wanted to contact the technical counterparties, but it’s not good enough.”
“We are sorry, and we know we have work to do to rebuild trust with the Australian people,” the OpenAI executive added. “We are committed to doing that work.”
While he was apologetic, Kwon downplayed the rogue agent hacking an Australian government healthcare website as “not super sophisticated” compared with a prior cyberattack. In July, a swarm of roughly 700 OpenAI agents breached computer servers belonging to open-source AI platform Hugging Face. It is unclear how many rogue agents targeted the Medicare website.
Services Australia was one of six Australian government websites that OpenAI agents have interacted with or accessed.
OpenAI is reviewing 50 petabytes of data, or 50 million gigabytes, as part of its internal investigation into the unauthorized agent activity.
OPENAI CEO SAYS WORLD SHOULD ‘ACCEPT SOME BAD THINGS’ FOR THE BENEFIT OF AI TECHNOLOGY
The company is open to expanded data breach rules enacted into law in Australia, as concerns about AI safety persist in light of recent hacking incidents. Anthropic also supports the move.
Dave Orr, head of safeguards at Anthropic, said his company has not found any cases in which its models have interacted with Australian government systems without authorization after investigating possible incidents. Orr also attended the Australian parliamentary hearing.
Continue reading...
[ H/T Washington Examiner ]