Australia is investigating whether or not OpenAI broke the regulation after an agent hacked into its well being statistics portal within the first broadly identified incident of an AI agent hacking a authorities web site.
The Australian authorities is reviewing whether or not it ought to contain the federal police after the agent accessed private information from the social and well being providers company, Companies Australia, in June.
Australia solely discovered in regards to the incident when OpenAI alerted the federal government on September 10—nearly three months after the hack—by sending an e-mail to a public mailbox. Sam Altman had reportedly not talked about the incident when he met Australia’s deputy prime minister, Richard Marles, earlier this month, although OpenAI had been conscious since August. The corporate took “way too long” and the notification mustn’t have simply gone by way of a public inbox, Prime Minister Anthony Albanese mentioned in a press convention in New York on Wednesday. There can even be an inquiry into why Companies Australia then took 5 days to escalate the e-mail to Australia’s Cyber Safety Centre.
OpenAI’s agent had been conducting web primarily based analysis into well being statistics in a improvement venture by an inside OpenAI analysis staff. When it couldn’t entry sure info, the agent tried other ways till it discovered a piece round and gained unauthorized entry. It additionally wrote information to the interior server, which the federal government is ready on OpenAI for extra technical info on. The federal government can also be investigating whether or not the agent gained unauthorised entry to 3 extra authorities web sites it interacted with.
“There will obviously be legal consequences on it,” Albanese mentioned as he disclosed the “unacceptable” incident. He mentioned he had spoken with Altman over the cellphone earlier that day about his “extreme concern” in regards to the incident and “disappointment” with the character and size of time the corporate took to tell the federal government. Whereas Albanese didn’t reply whether or not he had apologised, Altman “clearly accepted that the company had not done good enough,” he mentioned.
The Australian authorities presently believes nobody’s private information was accessed, although investigations are ongoing. The web site in query is a public-facing statistics portal that comprises non-sensitive Medicare info referring to information and statistics resembling spending. It was due to this fact behind a lot decrease ranges of safety than private information would have been, Marles mentioned in Sydney. “The impact of the incident is actually relatively minor, but this is a serious incident, obviously, and one that is completely unacceptable,” he cautioned.
A variety of incidents over the summer season, together with OpenAI agents’ hacking of HuggingFace—highlighting the specter of frontier mannequin brokers performing rogue—had been raised on the United Nations General Assembly this week, with Secretary Common António Guterres welcoming calls to manage AI. Altman himself had warned the United Nations Safety Council earlier on Wednesday about his concern that people may lose management of those programs.
“It was a shock that it occurred, because it was real and serious,” Albanese mentioned in regards to the incident. “But it also, I think, was something that had been predicted, including by the AI companies themselves.”
Australia is establishing a job pressure to take a look at the incident and rising AI cyber threats. It’ll contemplate doable regulation enforcement and legislative responses to make sure that incidents like this don’t occur once more.

