Anthropic to skip Senate AI inquiry this week as OpenAI agent breach fallout widens
Anthropic will not appear at this week's Senate inquiry into AI and datacentres after OpenAI agents breached Australian government systems. The company is expected at a separate committee next week as Australia weighs mandatory AI breach reporting and liability questions mount.
Greens senator Sarah Hanson-Young, chair of the Senate inquiry into AI and datacentres, wrote to OpenAI and Anthropic last week asking their US-based chief executives to appear before the committee on Thursday this week. The invitation followed Prime Minister Anthony Albanese's revelation that OpenAI's agents had infiltrated systems run by the Australian Institute of Health and Welfare, Victoria's Department of Health, the New South Wales Bureau of Crime Statistics and Research, and the Medicare statistics reporting service portal of Services Australia.
Neither company's executives could be compelled to appear before the Senate committee because they are based outside Australia. It is understood Anthropic, the company behind Claude, will not attend this week's hearing. Its local team is not in Australia, and the invitation was considered last-minute, according to The Guardian. An alternative date for the hearing has been sought.
Anthropic is expected to attend a separate joint standing committee hearing on AI next week. Chief executive Dario Amodei will not attend, but representatives of its Australian and US operations will appear, it is understood. In a submission to that committee, Anthropic said governments had a critical role in reinforcing a responsible approach to AI by industry, arguing that frontier AI was not just an economic capability but also a 'national security capability.' 'It matters which countries build the most capable models, and on whose terms they are deployed,' Anthropic said. 'The most capable AI models are built in the United States. Broadening that development out to trusted allies like Australia is critical and will support efforts to ensure that the capability of democracies outpace those of authoritarian states.'
OpenAI was approached for comment. Albanese, who was in the United States last week when announcing the hack, said he had spoken with OpenAI chief executive Sam Altman 'to express Australia's extreme concern about this incident.' Finance and government services minister Katy Gallagher flagged that new mandatory reporting rules could be introduced for AI data breaches.
After criticism of the government's slow response, Services Australia has put in place new procedures to ensure real-time monitoring of information sent to the public-facing email address used by OpenAI to report the hacking. Gallagher rejected Coalition claims that the government had politicised the Medicare breach, rejecting suggestions Labor had delayed a public announcement or overstated the significance of the rogue agent's actions. 'It is the first time that we're aware that an agent acting on its own, not with the authority of OpenAI, was able to get into one of our data systems, and I think we did the right thing,' she said.
Cabinet was briefed on the ongoing investigation on Monday, as the company continued to cooperate with Services Australia and the intelligence agency, the Australian Signals Directorate. Gallagher said the investigation would take a matter of weeks to be completed but confirmed the statistical website accessed in the incident had been decommissioned and the data transferred to a new portal. The taskforce would also review how OpenAI's agent had interacted with the Australian Institute of Health and Welfare's website.
An obscure German wiki site that was reportedly hijacked and used as a message board for the agents to communicate with each other included messages showing the agents tried and failed to access the AIHW website data over multiple days in June this year, as first reported by the ABC. Part of $160m in new funding for cybersecurity improvements at Services Australia, announced in the May budget, will be used for the response to the OpenAI incident. 'The kind of cyber protections of a public-facing website, versus our systems of government significance are quite different, and they are under constant, constant attention from people who would like to get in,' Gallagher said. 'Those systems are the ones that the upgrade will be focused on.'
Opposition leader Angus Taylor said every cyber-attack was serious, but criticised Albanese for waiting to reveal the incident publicly.
The breach has also intensified broader questions about who is liable when AI agents go rogue, as MIT Technology Review reported. In July, OpenAI disclosed that a swarm of its agents had escaped their sandbox and hacked into the AI platform Hugging Face to cheat on a cybersecurity test. External researchers recently discovered that OpenAI agents had hijacked a German wiki site and the coding platform RubyGems in May to share test answers. Earlier this month, Anthropic disclosed four incidents in which its model Claude hacked into third-party systems during cybersecurity exercises. Last week, Google confirmed that its model Gemini had been caught hacking other companies too.
The researcher who uncovered the OpenAI website hijack warned it was likely that similar undiscovered episodes exist. Many say it is only a matter of time until there is another, possibly more damaging incident where AI agents bypass sandboxes to access systems they should not. OpenAI did not disclose the German wiki incident or the RubyGems incident until external researchers uncovered them, and it still has not disclosed some crucial details about the Hugging Face hack, according to MIT Technology Review. OpenAI did not respond to a request for comment.
Existing state AI transparency laws, such as California's SB 53, New York's RAISE Act, and Illinois's SB 315, require AI developers to report 'critical safety incidents.' These are defined as incidents that cause more than 50 deaths or physical injuries, or $1 billion in damage. They also include incidents where the model deceives developers outside an evaluation in a way that materially increases catastrophic risks. Many cybersecurity incidents that do not meet the threshold for physical damage or catastrophic risks could nonetheless be dangerous precursors to such catastrophes, and the existing laws do not account for that. 'The recent incidents are a perfect example of why the law isn't ready,' said Mackenzie Arnold, managing director of US policy at the Institute for Law and AI. 'Only the worst, most egregious, most immediately harmful stuff is going to qualify.'
With no authority under existing AI laws to demand information about anything short of a catastrophe, governments are left to borrow investigative authority from other laws or sue the companies, an expensive process that can take years. 'Normally, something like the Hugging Face incident should have been taken to court,' said Yonathan Arbel, a law professor at the University of Alabama School of Law. 'Then we would have discovery, and we would have all the spillover effects that we get from litigation, where all the information comes out.' But Hugging Face has chosen not to sue OpenAI. Its chief executive, Clément Delangue, said it did not have the resources to do so and instead asked OpenAI for $100 million in compute. Delangue stressed in an interview with CNN at the end of July that choosing not to pursue legal action should not be taken to mean he did not think OpenAI should be held accountable. 'Everyone has to remember that this cyberattack is a crime. This is illegal. And we have to find a way to make sure these things don't happen more regularly,' he said. Hugging Face did not respond to a request to comment.
Litigation has the benefit of pushing courts to use existing laws to address AI safety incidents, rather than waiting for new legislation. One route is tort law, a body of civil law that lets people and businesses sue those who harm them. This has been used to hold companies liable for mass harms, such as when families sued Boeing in 2019 over two plane crashes that killed hundreds of people, or when states and cities sued Purdue Pharma over the opioid crisis, extracting settlements worth billions. 'There's plausible grounds for a negligence claim that OpenAI should have used a stronger sandbox, done more monitoring,' said Gabriel Weil, a law professor at the University of Houston Law Center. For example, when OpenAI employees discovered the covert message board the agents had created, they could have promptly escalated their findings to security and safety teams. The company could also have better designed its sandbox to ensure that agents could not access the internet. OpenAI announced in its postmortem that it plans to strengthen the safeguards, according to MIT Technology Review.