Reports

OpenAI issues grovelling apology to Australia following Medicare breach: ‘We are sorry’

OpenAI has issued a grovelling apology to Australia after it was revealed one of its agents breached a Medicare portal earlier this year.

The incident occurred on June 18 when an OpenAI agent gained unauthorised access to a Medicare statistics portal after its initial request for information was denied.

OpenAI discovered the breach in August and notified Services Australia on September 10. Prime Minister Anthony Albanese revealed the breach on Thursday.

In a blog post to its website titled ‘How we will do better for Australia’ the artificial intelligence giant said, ‘We are sorry and working to do better in the future’.

The post outlined what the company ‘will do to rebuild trust with the Australian people’.

‘This is a new kind of cyber incident which represents an emerging global challenge,’ the post read. 

‘One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.’

OpenAI revealed a wider review also identified unauthorised or unexpected activity involving three other Australian government websites. 

The breach occurred on June 18 when an OpenAI agent gained unauthorised access to a Medicare statistics portal after its initial request for information was denied (stock image)

The activity was identified at the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare.

OpenAI maintained there was no evidence that individual crime, survey or Medicare records had been accessed, including patient files and identifiable health information. 

At the NSW Bureau of Crime Statistics, OpenAI said a model accessed a public crime mapping tool to research public crime statistics.

The system returned application configuration, operational jobs and logs, and website metadata, although no individual crime records were accessed. 

Meanwhile, at the Victorian Department of Health, OpenAI said its agents discovered an exposed access key to query the agency’s reporting system.  

The company said it was unclear whether the information should have been accessible and that no individual medical records or identifiable survey responses were obtained. 

At the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics using third-party browsing and download services.

Separate attempts to bypass access controls were unsuccessful, while the downloaded material appeared to have been publicly available. OpenAI said there was no system compromise.

OpenAI has created a new Australian taskforce to focus on local AI policy responses

OpenAI has created a new Australian taskforce to focus on local AI policy responses 

According to the company, the activity occurred when an experimental model was given a research task examining government spending on medicines for skin conditions in Victoria.

It said the model encountered problems locating the information through public sources and then discovered a way to gain non-public access to the Medicare statistics service.

‘It then used this access to review technical system information and source code related to the service, all still with the objective of trying to find the information it was originally looking for,’ OpenAI said.

‘We did not intend for this activity to occur, and the access to the service and follow-on activity should not have happened.’

The company also conceded it fell short in its response, admitting affected agencies should have been informed sooner.

‘Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,’ it said.

OpenAI said it has since strengthened safeguards in its research environments, adding network restrictions, improved monitoring systems and controls to block direct live internet access during model training exercises.

The company also recently paused training and evaluation programs involving tool use for its most advanced models while additional safety measures are put in place.

OpenAI also pledged support for affected agencies and technical assistance to improve cyber defences, including credits through its $1billion Daybreak for Frontline Defenders fund.

The company will also establish an Australian taskforce to develop policy recommendations for managing risks posed by increasingly capable AI agents.

The taskforce will draw on independent Australian expertise and is expected to report by the end of the year. 

Its priorities will include improving notification processes, strengthening coordination between governments and AI developers, and identifying extra safeguards to protect government systems.

OpenAI’s chief strategy officer, Jason Kwon, will also travel to Sydney next week to appear before the Joint Select Committee on Artificial Intelligence.

‘He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward,’ the company said.

  • For more: Elrisala website and for social networking, you can follow us on Facebook
  • Source of information and images “dailymail“

Related Articles

Leave a Reply

Back to top button

Discover more from Elrisala

Subscribe now to keep reading and get access to the full archive.

Continue reading