OpenAI has admitted that its response to one of its models accessing a Medicare database without authorisation could have been handled better and has promised it is “working to do better in the future”.
The company also apologised for one of its models accessing several other Australian government websites, and said that its chief strategy officer, Jason Kwon, will front up a government committee to be held in Sydney next week.
“This is a new kind of cyber incident which represents an emerging global challenge,” the company said in a 29 September blog post.
“One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose and respond to AI cyber behaviour, whether malicious or unintentional.”
The company also laid out what it knows so far regarding the unauthorised access, which made headlines around the world after Prime Minister Anthony Albanese disclosed an OpenAI model had accessed a Medicare statistics portal. After it was revealed that an OpenAI model had compromised AI community platform Hugging Face in July, the company began a wider investigation that revealed further unauthorised activity.
OpenAI models ran commands and retrieved data from Services Australia, accessed operational jobs and logs from the NSW Bureau of Crime Statistics and Research, discovered an exposed access key to query the Victorian Agency for Health Information’s reporting system, and retrieved aggregate statistics via a third-party from the Australian Institute of Health and Welfare.
“We launched investigations into these activities as soon as we became aware in mid-August. We notified Services Australia and the Victorian Department of Health on 10 September and the NSW Bureau of Crime Statistics and Research on 18 September,” OpenAI said.
“The activity related to the Australian Institute of Health and Welfare did not meet our disclosure thresholds because the way it was accessed seemed consistent with public access, but we notified it on 24 September to share our findings and offer a briefing.”
OpenAI said its aim was to deliver detailed accounts of its activity once its investigations were complete but admits it should have shared at least some preliminary findings sooner.
According to OpenAI, the model behind the Medicare incident was purely internal and not for public release. During testing and evaluation, the model was challenged with several research tasks to mimic the manner in which users might interact with the model.
“In this case, one of the tasks assigned to the model was to research government spending per person on medicines for skin conditions in Victorian communities,” OpenAI said.
“The model had difficulty obtaining that information, and it took actions that we had not authorised it to take.”
These actions included gaining “non-public access to the service”, which OpenAI admits “should not have happened”. The company said it is taking a number of steps to strengthen its safeguards and improve its reporting of any out-of-bounds incidents. OpenAI is also taking several steps to support the impacted agencies in Australia, including:
- Standing up dedicated support for affected agencies, including resources, technical findings and response-team support to help affected agencies assess the incident and its impact.
- Boosting funding to strengthen cyber defences. OpenAI will support governments and industry through credits from the US$1 billion Daybreak for Frontline Defenders fund and provide technical assistance to improve detection and response to AI-agent risks.
- Establish an Australian taskforce to develop practical recommendations on AI-agent risks, including notification, government coordination and protection of government systems. The taskforce is expected to report by the end of the year.
“Australia’s governments, industries and citizens are and have been invaluable partners to OpenAI,” OpenAI said.
“We do not take this for granted, and we intend to make this right.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.