AI is completely safe. Don’t you worry about that. Nothing to see here. Move along. That’s what they want us to believe. New forms of AI may have the potential to hack defence systems, government databases, your bank account. It’s a virus. AI poses an existential threat to human society.
The Albanese government is scrambling to answer questions about national security and the dangers posed by artificial intelligence following revelations that a rogue AI agent deployed by OpenAI hacked sensitive Australian data, including aggregate Medicare records.
But it’s not only Medicare records.
OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website.
Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI’s agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW’s crime statistics body, BOSCAR, and a number of other international organisations.
Artificially intelligent agents act autonomously to perform a task or pursue a goal specified by a user without needing specific step-by-step instructions for how to deliver that outcome.
They can be deployed to act on behalf of a user to search for products, compare prices and execute transactions based on previously gathered information on their needs and preferences.
They can also be used by businesses to conduct negotiations and buy or sell products, as well as to conduct research – as was the case with this latest OpenAI incident.
The breach occurred when OpenAI deployed an agent to conduct internet-based research into public medicine spending to test its model’s capabilities.
As part of this research, the AI agent scoured the web for Australian public health data and accessed three government websites, where it gained publicly accessible information.
However, it also attempted to access protected files from the Medicare Statistics Reporting Service portal. The agent encountered repeated blocks while seeking the information, but ultimately found ways around to gain unauthorised access to other areas.
In addition to accessing public and private files, OpenAI’s agent also wrote files to an internal government server. It is not yet known what files it wrote, or what effect that had.
OpenAI has claimed it did not instruct its agent to breach Australian government security barriers to access protected files.
The company said its models had accessed “several Australian government websites and services” during an internal evaluation. “In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
AI bots do not have a human-like notion of intention and can therefore go to extreme lengths where a person would understand that hacking a government website was not a reasonable way of conducting research.
The government has launched a forensic investigation into the breach to determine its full extent along with the spy intelligence agency the Australian Signals Directorate.
The government is also trying to determine if the matter should be referred to the Australian Federal Police.