OpenAI Says ‘Oops-Sorry Australia

OpenAI published an open letter to Australia’s government, admitting that several more governments websites that were breached & promising to “do better.”

You can read the letter here. Ryan McCurdy, VP, Liquibase (https://www.liquibase.com/) says this:

“At this point, we have enough examples to know this wasn’t just one agent doing something unexpected against Medicare. Different agents accessed different government systems in ways OpenAI didn’t authorize. We should assume AI agents will occasionally take actions their operators didn’t expect and build around that.

“The agents didn’t need or have malicious intent. It was simply given a normal research task, and when it couldn’t find the information it wanted, found another way into the system, and kept going. 

“An agent can be trying to do exactly what it’s asked to do and still make a bad decision. If it has enough access and authority, that decision can become a security incident.

“The open letter aside, I think OpenAI is doing the right things. They’ve restricted live internet access in these environments, expanded monitoring, paused tool-use training and evaluation for their most capable models, and committed to working directly with the affected agencies. But we can’t rely on better models and better monitoring alone. The controls also need to sit outside the agent.

“Pausing its latest top models makes sense while OpenAI figures out what happened and puts additional safeguards in place. But we can’t pause AI every time an agent does something we didn’t expect. We have to start by assuming it’s going to continue to do so. 

“AI makes decisions based on probabilities. We can’t let those decisions automatically become actions against critical systems.

“Any company deploying agents needs to decide what an agent can access, what it can change, what it can decide on its own, and where policy or a person needs to make the call.

“Permission and authority are two different things. Design the AI SDLC so the governed path is the easiest path. Give agents the freedom to move quickly while keeping controls over critical systems outside their reach.

“The agent shouldn’t get to decide that its own high-risk action is safe.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://suzulabs.com/home-suzu-labs) says this:

“It is good that OpenAI says it will do better, but if the company were truly committed to accountability, we should see full cooperation with law enforcement, preservation of logs and evidence, and consequences for the people responsible for these security failures. If I accidentally hacked one organisation, let alone multiple organisations, I would not expect to get by with a promise to do better. I would expect an investigation. Criminal charges should follow if investigators determine that offences occurred. Until then, OpenAI’s response looks more like an attempt to turn a legal problem into a public-relations exercise.

“OpenAI said it would pause its top models – that’s not enough. If this were a one-off case, I would be more sympathetic, but this is a pattern of behaviour involving OpenAI agents bypassing controls, accessing systems and pursuing objectives beyond their authorised scope. A pause without a clear timeline, independent testing, release criteria or mandatory reporting requirements is little more than a platitude. I view it as an attempt to deflect attention from potential criminal liability and turn what should be a legal and security investigation into a public-relations exercise. Training pauses do not fix the underlying oversight, access-control and accountability failures.”

I personally think that enough is enough. OpenAI has proven that it cannot be trusted. Therefore I hope that Australia punishes them severely. Because punishment isn’t going to come from the USA. Especially given this development over the last hour.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading