The Australian government has revealed the email sent by OpenAI warning that one of its models accessed a Medicare statistics portal without proper authorisation.
The letter is no more than five paragraphs, reads more like a handy hint about a security vulnerability, and does not mention any apology.
“We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au,” the letter reads.
“An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password. It was able to access this to read portions of internal files and settings, obtain a list of files, and create and read back a small test file on the server.”
The email – which was delivered via a public email portal – goes on to point out that OpenAI found no evidence that patient data was accessed, and a recommendation that the Australian government should “investigate the vulnerability and assess the changes needed to prevent it”.
The email was signed “Best, OpenAI Security Team”.
The company has since apologised for the incident, admitting in a September 28 blog post that “We also should have handled our response better. We are sorry and working to do better in the future.”
OpenAI’s belated apology and the details of its initial disclosure come as the director general of the Australian Signals Directorate, Abigail Bradshaw, described Australia's relationship with AI firms as reciprocal.
“It’s a give and take here. And I think what’s important also is to look at the content of that apology. It’s not just the headline. The apology is important. We shouldn’t miss that moment,” Bradshaw told the ABC’s RN Breakfast on Wednesday morning.
“But actually, look at the content of what OpenAI have set out there. That is not insignificant. They are actually agreeing to sharing, for example, preliminary findings. They have taken a really significant step in slowing down the release of the next model to ensure that guardrails and sufficient safeguards are put in place. They have given an offer of practical support.
“And in fact, that is consistent with our experience, with our engagement with not just OpenAI, but the other labs, Anthropic and others, over the last six months, and I think that’s a really important precedent for the way this relationship proceeds into the future.”
Bradshaw earlier told ABC News that engagement with AI firms is uncovering several vulnerabilities in government code.
“There has been work and engagement over the last six months utilising – including models that aren’t publicly available – to fortify the sensitive networks of, for example, financial institutions, health institutions, energy providers,” Bradshaw said.
That process enabled us to, with great speed, identify vulnerabilities in code and patch those prior to the rollout of that really important national process.”
Australia’s Department of Home Affairs has ordered a government-wide assessment of cyber security posture in the wake of the incident. It will prioritise Systems of Government Significance; a review is expected by the end of the year.
"AI is changing the environment in which we operate at extraordinary speed. Government systems need to keep up," Acting Home Affairs Minister Richard Marles said in a statement.
"We can't wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited."
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.