OpenAI used artificial intelligence to help draft an email informing the Australian government that its AI agent had hacked into key departmental websites.
However, an OpenAI executive told a parliamentary inquiry on Tuesday that he did not believe the company’s own technology had been used to draft the email, adding that the company needed to verify this, according to The Guardian Australia
An artificial intelligence agent developed by OpenAI accessed data held by Services Australia and three other government systems in June.
However, the company did not notify the Australian government until 10 September, despite becoming aware of the incident in August.
OpenAI first notified the Australian government of the incident through a five-paragraph email sent to Services Australia’s public disclosures inbox, [email protected], which was checked only once a day.
The company has faced criticism for failing to report the incident through a more formal or direct channel. This included a face-to-face meeting between OpenAI chief executive Sam Altman and Australia’s Deputy Prime Minister, Richard Marles, on 1 September.
The meeting took place nine days before OpenAI emailed Services Australia, nearly a month after the company first became aware of the intrusion on 18 June.
“We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au,” the email stated, according to The Guardian Australia.
“An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password. It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server.”
In the email, OpenAI said its investigation “found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access”, and sent information about the “affected URL” and “affected report”.
“We recommend that the team responsible for the service investigate the vulnerability and assess the changes needed to prevent it. We would be glad to brief your security team and provide supporting evidence as available.
“Best, OpenAI Security Team.”
The company also provided details of the affected URL and report.
