00:01The kind of broad outlines of this is that in June, one of OpenAI's models, its AI technology,
00:12was doing some kind of task. They said an internal evaluation, according to the company,
00:18and as part of that it was looking up information about Australian medical spending. As a result
00:25of that, it accessed a government website that is owned by Services Australia that releases
00:36aggregate health data information, so not individual patient records, but kind of top-level
00:41stuff about things like what kind of medications, how much we spend on it, that kind of stuff.
00:47And that information, some of which was not meant to be publicly accessed, was accessed
00:53by these models. That happened in June. The company says that it found out about this
00:59in August, when it was looking over its kind of the logs of what its AI models had been
01:04doing. As people have probably heard by now, there's been a number of kind of recent incidents
01:08where OpenAI's models and other models from other companies have been doing things that
01:13they weren't necessarily aware was happening. So when they discovered it in August, they said
01:19that they had then carried out kind of internal investigations, trying to figure out exactly
01:23what was going on, and then reported it to Services Australia on the 10th of September.
01:30It's now two weeks since then. We've kind of learned that the way that the government
01:34was informed about this was an email sent to the Services Australia inbox. So not exactly a kind of
01:40like high-level, you know, reach out, but kind of just, you know, sent to the email inbox that many
01:46of us
01:46would be able to email. And the government has said that's kind of why it's taken so long for this
01:52to now be announced by the Prime Minister. Yeah. Protocol aside, though, in terms of informing the
01:58government about this particular breach, if OpenAI found out about this in June and only really started
02:05looking at it in August, why did it take that long? Yeah. So what happened is it was conducting these,
02:12you know, internal evaluations in June. Amazon, we really apparently, it says, found out that,
02:18you know, its model had access to this website in August. You know, for context, these companies
02:23are doing, you know, incredible amounts of internal evaluations, which for the non-nerds out there,
02:30essentially means, you know, they're putting their AI models through various tests and tasks to see
02:33how it performs. And as part of that, you know, they're getting it to access the internet. They're
02:38saying, you know, when you want it to do a task, it finds out information from the internet that has
02:41often the most up-to-date information. And then as a result, you know, they aren't necessarily,
02:46and by they, I mean, OpenAI and the researchers internally, the people who are running these
02:50challenges, aren't, you know, necessarily holding the hands of these models. They're saying,
02:54can you do this? And it goes and comes up with all the ways that it could do that. Thinks
02:59of all
02:59the, or, and by thinks, I mean, you know, this is a model. So, you know, based on its technology,
03:04comes up with various, you know, plans of how to answer questions. So to kind of, I guess,
03:10to put it kind of bluntly, there's a lot of this kind of stuff happening in terms of these
03:15evaluations. They are putting it through their paces. They are looking at all parts of the
03:19internet, essentially like too much, definitely for a person who was over looking at, to keep
03:25an eye on. So it was only after they started reporting and finding out about these, what I
03:31think are kind of more serious incidents. People might've heard about the big one, the OpenAI
03:36hugging face incident, where it kind of hacked out of a sandbox and into another company.
03:41It's only since then that OpenAI has really turned the scrutiny back on what was happening
03:45internally. This seems to be one of the things that's kind of come out in terms of those
03:49investigations. You know, I imagine there is an enormous amount of data that they are looking
03:54through to understand what exactly their models have been doing online. And based on like some
03:59early reporting, essentially, you know, I understand this and this is yet to be fully confirmed,
04:04but it is kind of like, believed that some of this information that was accessed by these agents
04:10was not particularly secure. It was something that, you know, it wasn't like it had kind of,
04:16you know, broken through passwords or something that, it wasn't exactly Fort Knox is what I'm trying
04:20to say. And so as a result, you know, like, this was not necessarily a hugely technical task to access.
04:29But the fact is that these models are kind of looking all over the internet and kind of drawing
04:33everything in like a kind of open sea trawler that meant that they've captured this information
04:38as part of it.
04:39The complexity that I'm thinking about here is that this was done by an AI agent. We know we've
04:46had security breaches before and people, groups have been held responsible for it, right? Who can
04:52then be held criminally responsible for this particular action?
04:56Yeah, it's a great question and something that I think is really not clear in the law right now
05:02because, you know, Australian law and most law is essentially based on this idea that a person does
05:07something, a person is responsible for an act. In these cases, obviously, a person is in control of
05:13these models. You know, it's told them, do XYZ task. Now, to be clear, we don't know exactly what
05:18that task was. But, you know, you know, they're giving often very high level instructions. Can you
05:24solve XYZ? Can you, you know, for example, like, you know, you or I could easily say, can you look
05:29up
05:29how much Australians spend on a certain kind of medication? And...