you are viewing a single comment's thread
view the rest of the comments
[–] 12 points 4 days ago (2 children)

Reading the story it's not clear who set up the agent. It's an agent running on OpenAI but it's not clear whether they're saying a customer instructed an agent to hack the Australian medical board and got around guardrails to prevent that, or that they're saying their own internal work agent decided to hack the Australian medical board at random.

In both cases OpenAI has culpability. In the latter case, they should be held fully responsible.

  • source
  • hideshow 2 child comments
  • [–] 3 points 3 days ago* (1 child)

    My understanding is that it was the latter. From the ABC (Australia):

    How was the data accessed?

    As the government understands it, in this case, OpenAI gave an agent a "benign" task of trying to do research about public medicines spending.

    The model then searched the internet widely for the information, and came across the Services Australia portal.

    It then asked questions of the portal, but the portal didn't provide it with the requested information. As a result, it gained unauthorised access and secured information that wasn't public.

  • source
  • parent
  • hideshow 1 child comment