Home Latest Australia OpenAI says its bots broke into other governments’ websites

OpenAI says its bots broke into other governments’ websites

2
0

Source :  the age

Rogue OpenAI agents have hacked dozens of organisations around the globe, the tech giant has revealed, as the prime minister warns the breaches are more evidence the world risks losing control of the rapidly developing technology without a co-ordinated international response.

OpenAI announced on Friday (US time) – just days after the prime minister revealed OpenAI had hacked Medicare – that its rogue agents had breached dozens more organisations, including the United States government and universities.

Prime Minister Anthony Albanese addressed the US hack fresh off his flight from New York.ABC News

Anthony Albanese said on Saturday that Australia had acted in its national interest in going public with the breach, and he was unsurprised the autonomous agents had struck again. He called on OpenAI to explain the burgeoning number of security incidents.

“We now know that it wasn’t just the issue of the Australian sites that have been subject to AI agents accessing information without authorisation, but that there are dozens of cases, including US government sites,” the prime minister said, speaking on his return to Sydney from the United Nations General Assembly in New York.

Albanese said international collaboration would be needed to ensure human control was maintained as AI rapidly developed.

“The key risk is humans not being in charge of the rollout of this technology,” he said.

Albanese has been walking a tightrope between muscling up to tech giants – with the teen social media ban, a digital duty of care and now the OpenAI hack – and racing to shore up data centre investment worth billions of dollars to the Australian economy.

On Saturday, the prime minister rejected any suggestion the risks posed by AI should deter Australia’s data centre pursuit, arguing the country needed to help shape the technology because “we can’t stop it happening”.

In a lengthy blog post, OpenAI said it was had notified a slew of organisations that its agents may have bypassed security controls, impaired availability or “negatively impacted” websites.

The tech giant also disclosed agents had leaked 53 images from ChatGPT users. The company did not clarify if the images were AI-generated or identified real people, or when the images were posted.

Sam Altman, addressing the UN Security Council in New York earlier this week, is in the spotlight as his company comes under intense scrutiny. Bloomberg

OpenAI said it discovered the incidents while probing the inadvertent hack of online platform Hugging Face in July.

The websites that OpenAI’s agents accessed unauthorised included the US Department of Education, the Department of Commerce and the Securities and Exchange Commission (SEC), The New York Times reports, citing security researchers and a person familiar with the episodes.

OpenAI confirmed the commerce department and SEC incidents, while saying the investigation into the Department of Education breach was ongoing.

The New York Times said OpenAI’s technology tried to hack the US Department of Education website to gather data from the department’s civil rights office but failed, citing researchers from the AI research firm Transluce.

OpenAI co-founder and chief executive Sam Altman dodged questions from this masthead on Thursday (US time) when asked about the Medicare hack, refusing to apologise to the Australian government or explain why it took months for OpenAI to detect and report the intrusion.

OpenAI chief executive Sam Altman gives out autographs on the way to the White House.Carolyn Kaster

However, in a social media post on Friday (US time), Altman admitted that OpenAI had not been prompt enough in keeping affected organisations informed of rogue activity by its AI agents.

“We have not been as fast as we would have liked, but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organisations,” he said in the post.

Albanese announced earlier this week that an OpenAI agent had gained unauthorised access to a Medicare portal on June 18.

While the agent had broken into a defunct database of bulk billing rates and medicine usage and did not access any personal information, it still marked one of the first publicly disclosed cases of an AI agent breaking into a government website.

Albanese used the infiltration of the Medicare Statistics Reporting Service to highlight at the UN General Assembly the urgent need for countries to develop standards to ensure that AI worked for people, not the other way around.

Meanwhile, US President Donald Trump remains a staunch supporter of allowing AI companies to continue developing their technology without the fetters of excessive regulation.

In his speech to the UN General Assembly this week, Trump said his administration rejected the “globalist scheme” to regulate AI and added the US would officially rename artificial intelligence “superintelligence” in a bid to rehabilitate the technology’s ailing public image.

OpenAI said in its latest post that the investigation was focusing on “instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods.”

It added most of the actions it had reviewed involved AI models carrying out “mundane research tasks”, such as getting answers to questions from websites.

“Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service.”

With Bloomberg and Reuters

Cut through the noise of federal politics with news, views and expert analysis. Subscribers can sign up to our weekly Inside Politics newsletter.

Brittany BuschBrittany Busch is a federal politics reporter for The Age and The Sydney Morning Herald.Connect via email.
Rob HarrisRob Harris is the national correspondent for The Sydney Morning Herald and The Age based in Canberra. He is a former Europe correspondent.Connect via email.