Allie K. Miller
@alliekmiller
An AI agent hacked a government. Nobody told it to.
In June, an OpenAI agent doing a research task gained unauthorized access to Australia's Medicare statistics portal. Non-sensitive data, no personal records, task was "benign." Australia's PM stood up at the UN this week (the traffic in NYC is a delight) and called it a hack, and told Sam Altman he was extremely concerned. Fair.
This hack was likely using a non-public version of a model (they test guardrails-off versions before releasing the safer public ones), but OpenAI only discovered the hack in August. OpenAI disclosed it to the Australian government in September. That delay is a big concern for me.
Identity and authorization for AGENTS (not just humans) is now a board-level topic.
Also - how long until we see some sort of lawsuit where the defendant says, “Ohhh the agent did it, not us”?