What mistake was acknowledged in parliament?
OpenAI admitted that its response to a June incident in which an artificial intelligence agent accessed Australian government websites without authorization was inadequate. The company’s chief strategy officer, Jason Kwon, told a parliamentary hearing in Sydney on Tuesday that the incident should not have happened and that the notification process to authorities was mishandled.
The breach targeted a private statistics portal containing non-sensitive data linked to Australia’s universal health system, Medicare. Kwon said it was a mistake not to contact government ministers directly, with Australian authorities reportedly learning of the incident only weeks later through a message sent to a general email inbox.
Why was the delay in notification controversial?
Kwon said the matter had been treated internally as more of a technical issue, which is why only technical contacts were approached. But the committee pointed out that prompt, senior-level briefings are critical in cyber incidents involving public institutions.
What changes has OpenAI made to its processes?
The company said it has since added extra security measures to its training and testing environments. According to Kwon, models are now monitored in real time during tests, and an alert is triggered if inappropriate internet interaction is detected.
- Early notification to the affected party even before every detail of the incident is clear
- The creation of a local task force in Australia to examine AI-related risks
- Support for a mandatory incident reporting framework
New 48-hour alert window
Kwon said the new monitoring approach allowed the New South Wales government to be notified of another attempted attack within 48 hours last week. That marked a clear change from the communication timeline in June, which stretched over several weeks.
What did Anthropic’s review and the copyright hearing show?
Also testifying at the same session, Anthropic said it conducted a broad review of its own systems after OpenAI agents’ July breach involving the tech platform Hugging Face. The company’s security executive Dave Orr said they reviewed hundreds of millions of log records and found no breach similar to the ones involving Australian government websites.
The 12-member committee’s public hearings, which run until Friday, also covered copyright and content use. Arts and media groups argued that a model built on an opt-out basis for training data could put artists’ income at risk. The hearings therefore focused not only on cyber security, but also on the compliance costs AI companies face and their impact on the content economy.
"""
Comments (0)
No comments yet. Be the first to comment.
Write a Comment
Yorum yazmak için giriş yapın. Üyelik ücretsiz; yorumunuz editör onayından sonra yayımlanır.