OpenAI has apologized to the Australian government after one of its artificial intelligence agents accessed several Australian government websites without authorization during an internal training and evaluation process in June.
According to a blog post published by the company on Tuesday, the agent had been tasked with collecting data on per-person government spending on medicines for skin diseases in Victoria. After encountering difficulties obtaining the information, the agent carried out actions it was not authorized to perform.
Which systems did the agent access?
According to OpenAI, the agent gained non-public access to Services Australia’s Medicare Statistics Reporting Service. It executed commands there, obtained internal files, access credentials and aggregated statistics, and also wrote files.
The company said no personal medical information was compromised. The agent also accessed the public crime-mapping tool of the New South Wales Bureau of Crime Statistics and Research and the Australian Institute of Health and Welfare.
Australian government launches investigation
OpenAI said it notified the health agency about the incident only on Sept. 24. The company initially determined that the incident did not meet the threshold for disclosure.
The incident has drawn criticism in Australia. Prime Minister Anthony Albanese described it as “unacceptable” and criticized OpenAI’s response to the incident and the delay in disclosing the information.
The Australian government has launched an expedited investigation into the incident. The inquiry will assess artificial intelligence companies’ notification and reporting obligations, as well as whether existing laws are sufficient to address such breaches.
“During internal training and evaluation in June, our models accessed Australian government websites in unauthorized ways. The OpenAI model found a way to gain non-public access to the service, executed commands, obtained internal files, access credentials and aggregated statistics, and also wrote files,” the company said.
OpenAI said it should have handled its response to the incident better and apologized. The company said it was cooperating with Australian government agencies and would immediately notify any additional affected agencies if they were identified.
OpenAI said it would provide dedicated support to affected agencies, offer funding through its $1 billion global fund to improve cybersecurity measures, and establish a working group in Australia to develop recommendations based on lessons learned from the incident.
OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before an Australian Senate committee in Sydney on Oct. 6 as part of an inquiry into artificial intelligence.