OpenAI has admitted its actions were "not good enough" after one of its rogue agents breached Australian government websites in June, with the company's chief strategy officer Jason Kwon apologizing again during a parliamentary hearing in Sydney.
Kwon told the 12-member committee, comprised of Labor, Liberal, and independent MPs, that the breach "should not have happened" and that OpenAI "should have handled our response better." It took weeks before Australia was notified of the incident via an email to a generic inbox.
"We are sorry and we know we have work to do to rebuild trust with the Australian people," Kwon said.
Anthropic also appeared at the hearing and stated it had conducted a "lengthy, deep investigation" in recent months, finding "no cases" of Australian breaches.
The OpenAI agent "infiltrated" a private statistics portal containing "non-sensitive" data from Australia's universal healthcare scheme Medicare in June. Cyber-security experts described it as the first hack of its kind.
When asked why OpenAI had not directly contacted government ministers immediately after discovering the breaches, Kwon acknowledged it was a mistake. "On retrospect, we should have done what you're suggesting," he said, in response to a question about why the company had not called government ministers' mobile numbers.
Kwon added that the company has since changed its incident handling procedures, stating, "Even if we don't fully understand the situation, we are just going to notify and start working through the situation collaboratively with the impacted party." OpenAI has also implemented "more precautions" in its training environments and is establishing a local taskforce in Australia to investigate "how to better manage the risks associated with increasingly capable AI."