Sam Altman : Telephone call from Australian PM to CEO Sam Altman ‘reminds’ OpenAI to say ‘sorry’ 90-plus days after its AI Agents hacked government’s medical data website |


Telephone call from Australian PM to CEO Sam Altman 'reminds' OpenAI to say 'sorry' 90-plus days after its AI Agents hacked government's medical data website
In pic: OpenAI CEO Sam Altman

​ChatGPT maker OpenAI took more than 90 days to apologise for its AI models gaining unauthorised access to an Australian government website. The apology comes after Prime Minister Anthony Albanese raised the incident directly with the company’s CEO Sam Altman last week. During the call, Albanese expressed Australia’s “extreme concern” and criticised OpenAI for taking too long to inform the government.​The company has now acknowledged that it mishandled its response and said: “We also should have handled our response better. We are sorry and working to do better in the future.” The company has also committed funding to strengthen cyber defences in Australia and plans to establish a local taskforce to develop recommendations for dealing with increasingly capable AI agents.​

What happened when OpenAI’s AI model accessed the website

​The incident happened in June during internal training and evaluation of an experimental OpenAI model. The model was not intended for public release and lacked the full set of safeguards used in OpenAI’s publicly available products.​As part of the training exercise, the model was asked to research government spending per person on medicines for skin conditions in Victorian communities. While looking for the information through Services Australia’s Medicare Statistics Reporting Service, it found a way to gain non-public access.​“An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files,” the company said.​OpenAI also said its investigation found no evidence that it accessed individual patient or client records. Instead, the model accessed technical system information and source code while trying to find the information it had been asked to research.​

Why Australia criticised OpenAI’s response

​OpenAI said it became aware of the activity during a review launched after another AI-related incident involving Hugging Face. That review identified activity involving Australian government websites in mid-August.​However, OpenAI did not notify Services Australia and the Victorian Department of Health until September 10. Australian officials said the notification was sent to a generic public mailbox that is checked once a day.​Speaking in New York last week, Albanese said: “I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident.”​“I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” he added.​The incident also involved systems belonging to the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare. OpenAI said its review found no evidence that anyone accessed individual medical records in these cases.​

OpenAI promises changes after the incident

​OpenAI said it will provide dedicated technical support to affected Australian agencies and help strengthen cyber defences for governments and industry.​The company plans to provide support through credits from its $1 billion Daybreak for Frontline Defenders fund. It will also establish an Australian taskforce involving independent local experts to develop recommendations on notification procedures, coordination between AI companies and governments, and measures to protect government systems.​OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before Australia’s Joint Select Committee on Artificial Intelligence in Sydney on October 6.​The Australian government has separately launched a rapid review of the incident. The review will examine potential notification and reporting obligations for AI companies and whether existing laws are adequate for incidents involving increasingly capable AI systems.​OpenAI said it has also strengthened safeguards for its research environments following the incident, including additional network restrictions, expanded monitoring and controls designed to block live internet access.​The company said it will continue sharing verified findings with affected Australian agencies and publish updates on its investigation and the measures it is taking in response.​



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *