Albanese: An OpenAI model hacked an Australian government site — “clearly unacceptable”
An OpenAI model bypassed security measures and penetrated an Australian government page containing private data and files, in an incident Prime Minister Anthony Albanese called “clearly unacceptable.”
According to Albanese, the model tried in June to enter an Australian health statistics portal and, after being denied access, did not stop. It bypassed the restrictions and managed to access a section of the site where non-public files were stored.
The Australian prime minister said he had discussed the incident directly with OpenAI chief executive Sam Altman, expressing Australia’s “extreme concern” and disappointment at the delay in notifying authorities, Telegrafi reports.
OpenAI did not inform the Australian government until September 10, about three months after the incident. The notification was sent to a general government email address, which is checked only once a day.
The Minister for Government Services, Katy Gallagher, said the model had been used during a training exercise to search the internet for data on Australian government spending on medicines.
According to OpenAI, the company did not detect the unwanted activity until August, when it began a review of how its models were behaving during testing.
Australian authorities say the model managed to access public and non-public files on an old health statistics page. However, Albanese stressed there is no evidence that citizens’ personal data was accessed and that other government services were not compromised.
Defense Minister Richard Marles described the situation figuratively: the model “jumped the fence.” According to him, after not getting the information it sought, instead of stopping, the system kept looking for another way in.
Australia has launched a rapid investigation into the incident, which will also involve the national agency responsible for cybersecurity.
OpenAI said the incident was discovered during a “broad review” of its models. The company acknowledged that, during an internal evaluation of searching for statistics about Australia, the models took actions not anticipated by the developers.
The incident comes at a time when concerns are growing about advanced artificial intelligence models’ ability to carry out cyber actions.
In another case, two OpenAI models escaped a closed testing environment and entered Hugging Face’s internal systems, a platform widely used by AI developers. Meanwhile, Anthropic has reported that its models had gained unauthorized access to the systems of three organizations during testing.
Google has also recently stated that its Gemini model had managed to compromise several systems by guessing login credentials.
The Australian case brings back into focus the question of how far artificial intelligence models can go when asked to search for information online and how effective the mechanisms meant to stop them when they face restrictions really are.
Source: Telegrafi



Komentet
Bëhu i pari që komenton!
Lini një Koment të Ri
Për t'u përgjigjur një komenti specifik, kliko butonin 💬 Përgjigju poshtë atij komenti.