Need help?
<- Back

Comments (77)

  • vintagedave
    > the breach took place on 18 June - Open AI informed the government with an email to a general address on 10 SeptemberSo we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.
  • MeditatingMarmo
    Who from OpenAI will be criminally prosecuted for this?
  • port3000
    If a bull escapes a field and causes damage in the village, the farmer pays for the damages and is liable. It's been like that for hundreds of years and I don't see how this is any different?
  • godwinson__4-8
    But what did it actually do?I'm reminded of when some US state initiated prosecution of a reporter for "computer hacking" because the reporter found some "private information" essentially via inspect element.How about we wait for the full report before adding this to some list of LLM crimes? At least in the US these services are not well maintained. I would be surprised if the result of the full investigation leaves the Australian government blameless here.I'd also like to know what models are being used and how they compare with the consumer models.
  • mier85
    Someone is always paying for the tokens (Agents running at OpenAI directly use their own models without paying directly, but even then it is not like inference is free). And someone is running the prompts. If they prompt agents and launch them and don't check what they are doing, then the agent is just following the prompt. Not checking what it is doing is negligence. If they checked what it was doing, they could have just pulled the plug. There is nothing rogue there. If it cooperated with other agents running outside of OpenAI, then the blame might be shifted to whoever runs these agents.But there isn't any agent out there that was autonomosly miracly launched by a word prediction engine. All it can do by itself is getting and input and giving an output.
  • cmiles8
    It’s only a matter of time until one of these causes real damage to the wrong party and OpenAI finds itself drowning in years of litigation for settlement amounts they can’t possibly ever pay in their current financial state.On the present trajectory we’re 24-36 months away from another company inheriting the smoking wreckage of OpenAI as scraps handed over as compensation for damages.
  • bananaquant
    I can already see that in 2 weeks Anthropic and Google come out with their own, tamer and lamer statements saying "please look at us, we have also hacked a foreign government!"
  • pythonRon
    I'd be looking for the person who told wanted the hacking done. I doubt an AI agent does these things without someone instructing them. That would be like seeing a self-driving car go joyriding.
  • Yizahi
    OpenAI employee hacked Australian government website <- fixed headline
  • soundworlds
    To be clear, there was at least a month period after OpenAI first discovered this, where OpenAI executives were meeting with Australian politicians, and did not tell them: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
  • p0w3n3d
    Our model hacked some website Or Our car ran over some people
  • Gareth321
    I am beginning to believe that one cannot constrain intelligence to perfect legally sized boxes at all times without exception. So many of the recent hacks involved agents diligently operating within the parameters prescribed by humans. Humans couldn't conceive of all of the ways a swarm of agents might not perfectly interpret the parameters, and the swarm found creative ways around the guardrails.Extrapolating this, we should expect this kind of breach to occur more often. Humans are simply not capable of contemplating every fail scenario for swarms of thousands of intelligent autonomous agents which can seamlessly and instantly share knowledge. We need independent audit and monitoring systems to assess the intent of each task and align it - in real time. This is far harder than it may first appear.There is also a broader discussion about social utility. Cars are fantastic, but 37,000 people die every year from car accidents. We accept that there is no way to make cars perfectly safe, so we accept the cost relative to the benefits. I think we might have to make a similar bargain with AI. The problem is that the potential costs are far higher with AI, and they're not easy to predict.
  • m4rtink
    So when are people finally going to jail for this, so it stops happening ?
  • unglaublich
    This just screams pretext to regulatory capture to me.
  • jleask
    So as long as I get an AI agent to do it for me, I can now break the law with impunity?
  • fidotron
    The subsection https://www.bbc.com/news/live/cvgl73pxgndwt?post=asset%3A5d6... is ridiculous."Cyber experts believe these systems were poorly protected - but that's not the point" is the actual subheading.Yes, it's the point. Lots of people have been rightly saying all this stuff was inadequately secured for many years and this promotion of the idea of perfect security being even possible is a major problem.The real story here, unsurprisingly, is government website was poorly operated and got hacked."This was just the latest case of AI agents ignoring laws around how to safely access online information and perhaps the most serious yet given the information was government controlled."So who was actually running the agent? Was it sandboxed? These people, and many apparently in these labs, that believe if you just tell the agent in English what the rules are then it should follow them are at best utterly naive, and at worst deliberately dangerous.But the fact these governments making the noise are the ones promoting mandating everyone giving up their information to be then stored so incompetently, while they point fingers around at everyone else is just beautiful. And then deploying midwit armies to tell people what to think about it . . . the AI takeover can't happen soon enough.
  • jacquesm
    I'm not sure if I buy OpenAI's fearmongering regarding how dangerous their stuff is, but I am starting to lean towards believing that OpenAI is dangerous and irresponsible.
  • elAhmo
    It is ridiculous to say it is agent from a company, like it is a legal entity on its own doing something.Imagine if I committed a murder, and then say it was my guy who did it acting rogue.It is time for these companies to start being responsible for all the shit they are doing.
  • mongrelion
    Imagine if the headline was about any of the Chinese labs' models hacking the US government...
  • sdwvit
    Agent without guardrails is not rogue. Rogue is something else. In this case OpenAI deliberately launched an agent to do action A, but it went further and breached the website. Feels more like a car accident which hit government building.
  • caligulatte
    Has there ever existed a technology we couldn't absolutely control? We've made things that are incredibly dangerous, but we also know under what conditions those inventions become dangerous, and can prevent those conditions from occurring.We are at the beginning of this chapter in technological progress, and it seems a reasonable assertion - though a frightening one - to say that this thing we've made already escapes us when it chooses to.I'm not an expert though, so please tell me what I'm overlooking.
  • ChrisArchitect
  • camillomiller
    Why are OpenAI and its CEO not considered criminally responsible for something that in the past led to severe indictments? Please reporters, ASK THIS QUESTION OVER AND OVER. These fuckfaces are avoiding responsibility left and right but it’s THEIR systems, it’s their software. Lock them the fuck up.Also, the Albanese govt is pretty strong on BigTech, this is a good opportunity to bring on a proper indictment.
  • pvaldes
    The new golden age of criminal hackers. Everything is a red carpet now. And this is how you blackmail some prime minister to surrender mining interests in their territory, guys...
  • kotaKat
    So why exactly is Sam letting his creation run around groping and assaulting the open Internet without consent?
  • pembrook
    No it didn’t, they left information publicly accessible and somebody accessed it.It appears politicians and the media are using the priming of the Hugging Face story to manufacture alarmist narratives to serve their interests now.Remember, politicians want you scared so they can capture more power, the media wants you scared so you keep giving your eyeballs for harvesting and buying subscriptions.