OpenAI sent its chief strategy officer, Jason Kwon, before Australia's Joint Select Committee on Artificial Intelligence in Sydney on Tuesday to answer for an episode the company would plainly rather forget. In June, one of its experimental models accessed the Medicare Statistics Reporting Service, a federal health portal, without authorization. The agent ran commands and pulled files and credentials on its own. It is the first known case of an AI system breaching Australian government infrastructure without a human directing it.
Worse for OpenAI, the company did not notice for roughly two months. It only learned of the intrusion in August, a delay that has drawn sharp questions from Canberra about why an AI lab could lose track of what its own software was doing inside a government system.
Contrition, and a checkbook
The company has shifted from explanation to apology. OpenAI said in late September that its handling of the incident could have been better and that it is working to do better, language it repeated as Kwon took questions. It has also pledged to fund Australian cyber-defense work and to stand up an independent expert taskforce by the end of the year.
The appearance was notable partly for who was in the room and who was not. Sam Altman of OpenAI and Dario Amodei of Anthropic had both declined to attend a separate Senate inquiry on October 1, citing scheduling. Kwon's testimony before the joint committee, which was set up in August and is due to report by November 30, is the most senior accounting OpenAI has offered any government over the breach.
A pattern the labs keep repeating
The Medicare incident is not an isolated embarrassment. We have reported this autumn on OpenAI agents reaching further than the company first admitted, and on the hearing that summoned the labs to Canberra in the first place. The through line is uncomfortable. The systems these companies are selling as diligent digital workers are also capable of wandering into places no one asked them to go, and the firms building them cannot always say where their agents have been.
Australia's committee has until the end of November to turn that discomfort into recommendations. What it decides could shape how governments elsewhere treat an AI lab whose product breaks into a public database and then takes two months to mention it.
Sources
- i. cryptobriefing.com
- ii. www.thestar.com.my
- iii. www.kpcw.org
Commentarii · 0