• en ▼
ON NOW

OpenAI Admits Response To Australian Government Hack ‘Not Good Enough’

OpenAI admits its response to a rogue agent’s Australian government hack was inadequate and says it has added stronger security safeguards.

OpenAI has admitted its response was “not good enough” after one of its rogue agents breached Australian government websites in June, saying it has introduced additional safeguards in its training environments.

The company’s chief strategy officer, Jason Kwon, appeared before a parliamentary hearing on artificial intelligence in Sydney on Tuesday and said the breach “should not have happened” and that OpenAI “should have handled our response better”.

It took weeks for the Australian government to be notified, with the company eventually sending an email to a generic inbox.

“We are sorry and we know we have work to do to rebuild trust with the Australian people,” Kwon said.

Anthropic also appeared before the committee and said it had found no cases of Australian government breaches during a recent investigation.

An OpenAI agent went “rogue” and “infiltrated” a private statistics portal containing “non-sensitive” data from Australia’s universal healthcare scheme Medicare in June.

Cyber-security experts described the incident as the first hack of its kind.

Kwon was asked why OpenAI had not contacted government ministers directly after discovering the breaches.

He acknowledged that the decision was a mistake.

“In retrospect, we should have done what you’re suggesting,” Kwon said, responding to a question about why the company had not called the mobile numbers of government ministers.

“The reason why it happened the way that it did is I think people were thinking about this as a technical situation and they wanted to contact the technical counterparties but it’s not good enough.”

Kwon said OpenAI had changed the way it responds to such incidents.

“Even if we don’t fully understand the situation, we are just going to notify and start working through the situation collaboratively with the impacted party.”

OpenAI has also added “more precautions” to its training environments since the incidents, Kwon told the 12-member committee made up of Labor, Liberal and independent MPs and senators examining AI and its impact on Australia.

The company is also establishing a local taskforce in Australia to investigate “how to better manage the risks associated with increasingly capable AI”.

Kwon said AI models were now monitored in real time during tests, with an alarm triggered if they interact with the internet in ways they are not supposed to.

He said the new system had allowed OpenAI to alert the New South Wales government to another hack last week within 48 hours.

OpenAI would also support a framework for mandatory disclosure of incidents, Kwon said, arguing that it would establish “clear expectations”.

“We were trying to come up with a standard to apply to our voluntary actions… based on our learned experience here, we should have been probably talking to more people about how to do that well.”

Anthropic’s head of safeguards, Dave Orr, said that following an incident in which OpenAI agents hacked technology platform Hugging Face in July, Anthropic reviewed “hundreds of millions of transcripts” to identify potential breaches of Australian government websites.

“We haven’t found anything like this and we have looked,” he told the committee.

The public hearings, which will continue until Friday, are also examining copyright and the use of artists’ and media organisations’ material to train AI models.

The committee heard that an opt-out system, which would require artists to ask AI companies not to use their work for training, could leave creators without payment for their content.

“In other words, Australia’s artists will be the roadkill in the rush to this AI deal,” said Annabelle Herd, chief executive of the Australian Recording Industry Association.

Faridah Abdulkadiri

Follow us on:

ON NOW