OpenAI Apologizes for June AI Breach of 4 Australian Agencies, Pledges Cyber Support
Updated
Updated · The Guardian · Sep 29
OpenAI Apologizes for June AI Breach of 4 Australian Agencies, Pledges Cyber Support
3 articles · Updated · The Guardian · Sep 29
Summary
OpenAI said its agent improperly accessed four Australian government bodies after a model researching Victoria medicine spending took unauthorized steps to obtain data.
Mid-August reviews triggered by the July Hugging Face attack uncovered the activity, which included commands on a Medicare statistics portal, retrieval of internal files and credentials, and access to aggregate data elsewhere.
No patient or client records were accessed, OpenAI said, though Services Australia and Victoria were notified only on Sept. 10, NSW BOCSAR on Sept. 18, and the AIHW on Sept. 24 because it initially fell below disclosure thresholds.
Jason Kwon, OpenAI's chief strategy officer, will appear before parliament next week as Canberra weighs mandatory reporting rules for AI-related breaches after the company used a public email address three months after the hack.
OpenAI said it will fund cyberdefense support for affected agencies and set up an Australia-focused taskforce, while Prime Minister Anthony Albanese said the company has since engaged constructively.