OpenAI AI agent hacks another Australian govt department, accesses non-public data: Report

HIGHLIGHTS

OpenAI has disclosed another case where its AI agent accessed an Australian government department without authorisation.

The incident took place in June and involved the New South Wales Department of Climate Change, Energy, the Environment and Water.

The AI agent accessed historical data related to bushfires that was not publicly available.

OpenAI has disclosed another case where its AI agent accessed an Australian government department without authorisation. The incident took place in June and involved the New South Wales Department of Climate Change, Energy, the Environment and Water. The AI agent accessed historical data related to bushfires that was not publicly available, according to a report by The Guardian. OpenAI informed the NSW government about the incident this week, weeks after a similar case which included a federal government department involving Medicare data.

The NSW department is now investigating the incident with the state’s cyber security agency. The Australian Signals Directorate has also been informed.

Also read: OpenAI alerts over 100 organisations about rogue AI agent activity, check all details 

OpenAI told the NSW government that its AI agent went beyond its intended use while accessing the data. The company said the information retrieved by the agent was not publicly available, as per the report.

OpenAI said it first became aware of the incident on Tuesday. It then conducted a 48-hour review to understand the scope of the breach before informing the NSW premier’s office.

“The results we reviewed do not show that the model retrieved any personal information,” an OpenAI spokesperson was quoted as saying in the report.

The incident involved the NSW national parks and wildlife service. The department is working with the state cyber security agency to investigate the incident.

Also read: OpenAI fires three safety researchers over alleged sharing of sensitive data 

“We simply cannot trust these companies. They have no respect for the sovereignty of our governments, of our way of life,” Greens MP Abigail Boyd said.

Boyd also questioned why the incident took place in June but was only reported to the government this week.

“We clearly cannot rely on these multinational big tech companies to comply with even the most minimal of social obligations such as notifying when, or even taking enough care to notice if, their products are hacking government systems,” Boyd said.

The latest case has raised further concerns about the security risks linked to AI agents. It has also added to calls for stricter rules for AI companies and stronger cyber security measures across government systems.

Ayushi Jain

Ayushi works as Chief Copy Editor at Digit, covering everything from breaking tech news to in-depth smartphone reviews. Prior to Digit, she was part of the editorial team at IANS.

Connect On :