OpenAI used AI to help write the email to the Australian government advising that its AI agent had hacked into key departmental websites, Guardian Australia can reveal. On Tuesday, one of the company’s executives told a parliamentary inquiry that he didn’t believe that its own technology had been used to create the email, but said the company needed to confirm this. Guardian Australia understands AI was used by OpenAI’s legal and security teams to generate parts of the wording of the email, including word selection and formatting of the message.
But a source with knowledge of the incident said humans reviewed the final email, and humans were responsible for actually sending the communication to the Services Australia inbox. An artificial intelligence agent developed by OpenAI accessed Services Australia data and three other systems in June. The company notified Australia on 10 September despite becoming aware of the incident in August.
The company’s first notification to Australia came in a five-paragraph email to a Services Australia inbox, [email protected], which was only checked once per day. OpenAI has come under fire for not raising the issue in a more formal or direct way, including during a face-to-face meeting between the company’s CEO, Sam Altman, and Australia’s deputy prime minister, Richard Marles, on 1 September, nine days before the company emailed Services Australia but nearly a month after it first learned of the 18 June intrusion. Jason Kwon, OpenAI’s chief strategy officer, admitted in a parliamentary hearing on Tuesday that the company’s “response was not good enough, and we should have informed the impacted parties much sooner”.
During the hearing, Liberal MP Aaron Violi – the shadow minister for technology – had asked Kwon specifically about the email and whether AI had been involved in its creation. When you notified Services Australia via email, did your staff use AI to construct that email?” Violi asked. Kwon responded: “I don’t believe so, but we’re happy to go and confirm.” Kwon indicated during the hearing that OpenAI would provide specific responses to more technical queries in answers to questions on notice.OpenAI is expected to provide more information about the email once its own investigation has concluded.
The email, obtained by Guardian Australia in September, advised Services Australia: “We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au. It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server.” The email advised that OpenAI’s review “found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access”, and sent information about the “affected URL” and “affected report”. We would be glad to brief your security team and provide supporting evidence as available.
Andrew Charlton, the assistant minister for science and technology, spoke about the OpenAI incident in a speech in Sydney on Thursday, describing the company’s agent as having “hacked into an Australian government system”. The assistant minister said “the market will not fix” issues with AI development, a contrast to the United States’ approach of letting companies operate with a degree of self-regulation. Charlton raised concerns that “frontier labs are putting capability ahead of safety”, positing that Australia can have the most impact on the development of AI by hosting and influencing frontier labs.
Extract — continue reading at the source.