Five things to understand about how the OpenAI hack unfolded
The Albanese government is scrambling to answer questions about national security and the dangers posed by artificial intelligence following revelations that a rogue AI agent deployed by OpenAI hacked sensitive Australian data, including aggregate Medicare records.
As officials continue to investigate what happened, and the global tech giant responsible for the agent faces a potential referral to police, here’s a run-down of everything we know so far about the incident.
While based on the same AI models as chatbots that have become mainstream, artificially intelligent agents are an increasingly common offering and tool for both users as well as organisations.
They act autonomously to perform a task or pursue a goal specified by a user without needing specific step-by-step instructions for how to deliver that outcome.
AI agents can be deployed to act on behalf of a user to search for products, compare prices and execute transactions based on previously gathered information on their needs and preferences.
They can also be used by businesses to conduct negotiations and buy or sell products, as well as to conduct research – as was the case with this latest OpenAI incident.
The breach occurred when OpenAI deployed an agent to conduct internet-based research into public medicine spending to test its model’s capabilities.
As part of this research, the AI agent scoured the web for Australian public health data and accessed three government websites, where it gained publicly accessible information.
However, it also attempted to access protected files from the Medicare Statistics Reporting Service portal. The agent encountered repeated blocks while seeking the information, but ultimately found ways around to gain unauthorised access to other areas.
In addition to accessing public and private files, OpenAI’s agent also wrote files to an internal government server. It is not yet known what files it wrote, or what effect that had.
Deputy Prime Minister Richard Marles likened the Medicare portal’s security to a “fence”, whereas he said Australians’ personal data held by government sat “inside a safe”, and sensitive national security information “sits behind a fortress”. This data was not national security information and was held on a “legacy” website, Finance Minister Katy Gallagher conceded, suggesting it was easier to access.
The breach has alarmed the government, including Prime Minister Anthony Albanese. “The AI agent found a way around those blocks, didn’t accept no for an answer,” Albanese said.
OpenAI has claimed it did not instruct its agent to breach Australian government security barriers to access protected files. The company said its models had accessed “several Australian government websites and services” during an internal evaluation. “In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
AI bots do not have a human-like notion of intention and can therefore go to extreme lengths where a person would understand that hacking a government website was not a reasonable way of conducting research.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.brisbanetimes.com.au — the content belongs to Brisbane Times.