The federal government could change Australian laws if the current legal framework could not respond to the unprecedented
OpenAI hack of
Medicare, ministers have confirmed.It comes as the prime minister denied accusations from the opposition he had held onto the information before announcing it at the UN general assembly in
New York, and said it was released at the first possible opportunity.“It’s just nonsense … I was informed while I’ve been in
New York,”
Anthony Albanese told News24 on Friday.“Imagine if we had said there’s been a data breach, but we don’t know what has been sourced, we don’t know if your personal information is out there, that would have created a great deal of anxiety, which was unnecessary.“We had to ascertain the facts, and then we made the statements, as a matter of urgency, we also provided briefings to the opposition, as is appropriate.”
Katy Gallagher, the government services minister, said she was informed about the breach on 17 September. Guardian
Australia understands she informed the prime minister between Friday 18 and Saturday 19 September.Albanese left for the
United States on the Friday, where he first met with Apple’s executive chairman
Tim Cook in California on Saturday morning, before flying to
New York that afternoon.On Friday, the government said the review by spy agency, the
Australian Signals Directorate, would consider whether legislative change was needed after the prime minister revealed an artificial intelligence agent developed by
OpenAI hacked
Medicare’s statistics website and three other systems in June.If current laws could not touch the tech giant, they would need updating, environment minister
Murray Watt said on Friday.“There’s now a review of this underway through that task force that we’ve appointed, and one of the things that they’ll be looking at is whether these matters can be referred to the
Australian federal police under current Australian law,” he told Channel Seven’s Sunrise program.“If that is possible to happen, then that will happen. If it’s not possible, then clearly that indicates that we need to change Australian laws, and that’s what we’ll be doing.”The assistant minister for technology and the digital economy,
Andrew Charlton, acknowledged similar incidents would become “more and more prevalent into the future” and the government would need to be prepared.“That’s why we’re conducting a review of the incident as well as a review of the laws to determine exactly … whether there needs to be legislative change to recognise this type of incident conducted by an AI agent rather than directly by a person or a company,” Charlton told ABC radio.
Anthony Albanese told the Asia Society on Thursday that the incident was a “wake-up call” about the risks of AI, and whether humans would remain in charge of the technology.“This technology is moving very, very fast, and we need to make sure that we have a responsibility to keep on top of it,” Albanese said.Labor has announced it would legislate an AI standard, which Charlton said would be informed by the rapid review. The government has said it wants the bill to be introduced by the end of the year.UNSW professor Lyria Bennett Moses, an academic expert in technology and law, said
Australia’s criminal laws should be clarified to determine how fault, such as intention or knowledge, is applied to a corporation when its AI agent commits a crime.skip past newsletter promotionafter newsletter promotionShe said existing laws are clear if a human or corporation gains unauthorised access to restricted data, but it’s more complicated when an AI agent commits the physical element of the offence.“The person is not the AI agent, so it’s not about what the AI agent intended. It’s about how you attribute that intention and that knowledge back to a corporation,” Bennett Moses said.Bennett Moses said existing civil laws are more likely to deal with these sorts of incidents, that would allow a government or individual to seek compensation an AI company for harm “negligently caused by that corporation”.“If their systems have suffered harm and there is financial loss, and that harm was caused by the negligence of a corporation, you’ve got a potential for litigation to get compensation for that harm,” she said.“Here it seems to me much easier to hold a company liable, because if a company caused the harm, it’s not a defence to say that my bot did it.”The opposition leader, Angus Taylor, told reporters the opposition would be open to working with the government to hold companies accountable.“I’ve long believed that data breaches need to be dealt with in an appropriate way and those responsible for the data breaches need to be accountable for it … But we’ll wait and see what the government has in mind.”
OpenAI spokesperson Drew Pusateri said on Thursday the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems”.“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about
Australia during an internal evaluation,” Pusateri said in a statement.Pusateri said
OpenAI was supporting investigations and that its review was ongoing, adding it was committed “sharing what we learn as that work continues”.