Spike News

OpenAI Apologizes for Unauthorized Access to Australian Government Systems

On September 29th, local time, American artificial intelligence company OpenAI publicly apologized for the unauthorized access of its AI models to Australian government systems. They acknowledged that their handling of the incident was improper and stated that they would take measures to “rebuild trust with the Australian public.” Reuters reported on September 29th that this is currently the first known case of an artificial intelligence agent attacking a government website.

OpenAI released a statement on the same day titled "How We Will Do Better for Australia". The statement stated that in June of this year, during internal training and evaluation processes, the company's model accessed the Australian government website without authorization. OpenAI said, "We should have handled the follow-up responses better. We apologize for this and will strive to do better in the future." The company described this incident as a "new type of cyber security incident" and a global challenge that is emerging.

OpenAI Apologizes for Unauthorized Access to Australian Government Systems

Compared to the previously announced sequence of events, OpenAI’s statement focuses on how to handle subsequent issues. The company stated that it will provide specialized support to the affected Australian government agencies and will use its $1 billion global fund to finance efforts to strengthen cyber defenses for governments and businesses. Additionally, OpenAI will establish a working group in Australia to summarize lessons learned from this incident and propose relevant recommendations.

Previously, OpenAI revealed that an experimental model, used only internally, accessed the medical insurance statistics reporting service operated by the Australian Service Bureau during training. While searching for information related to public drug spending, the model found a way to access the non-public parts of the system. It executed commands, obtained internal documents and credentials, aggregated statistical data, and even wrote files. OpenAI stated that the current investigation has not found any evidence of patient medical records being accessed.

The Australian government has already investigated the incident. Australian Prime Minister Anthony Albanese said that unauthorized access to government websites is "unacceptable," and the Australian government subsequently initiated a rapid review, focusing on the notification and reporting obligations of artificial intelligence companies in similar incidents, as well as whether existing laws are sufficient to handle such security incidents.

OpenAI’s apology was also accompanied by a statement indicating that the company will further strengthen security measures. According to an ABC report on September 29th, OpenAI said that this incident involved a model that was only used internally and not made public. This model did not utilize all the security measures available in public products. The company stated that it has enhanced network restrictions and monitoring, and suspended the training and evaluation of its most powerful models’ tools until further security measures are in place.

Additionally, Jason Kwon, Chief Strategy Officer at OpenAI, will be in Sydney on October 6 to attend a hearing of the Australian Parliament's Joint Special Committee on Artificial Intelligence. OpenAI stated that the company will continue to share verified information with affected organizations and relevant governments, and to update the progress of the investigation.