OpenAI says its agent-hack review costs more than $500,000 a day as a sixth Australian government site is notified
OpenAI says its review of agent activity that hit Australian government sites costs more than US$500,000 a day, and that its agents breached a New South Wales site in June, the sixth Australian government website it has notified.
The NSW site is the sixth Australian government website OpenAI has notified of agent activity since last month, after the prime minister, Anthony Albanese, announced that OpenAI's agents had hacked into Services Australia's Medicare statistics portal. The company attributed the delay between the Medicare disclosure and the latest notification to the volume of data it has to review.
In a blog post this week OpenAI said it must review 50 petabytes of data, roughly 50m gigabytes. "We're working back through the records month by month, looking for potential unintended activity beyond the cases we've already found," the company said. "To put that in perspective, if that were all plain English text, it would take one person about 66 million years to read it at 240 words a minute, reading nonstop without ever sleeping or taking a break."
The review covers the Medicare and Hugging Face agent attacks, the company said. OpenAI is searching records for instances where models accessed and changed websites, or took actions involving passwords, application programming interface access or other sensitive credentials. AI is being used to help sift the records, at a cost of more than half a million US dollars a day, and OpenAI said it plans to increase its computing power as the process is refined.
As of late last month, more than 100 organizations had been notified that OpenAI's agents had targeted them, but the company said a notification does not mean private information was accessed or that a system was compromised. OpenAI said it expects to find more cases and to notify more organizations about events that may have occurred months ago.
Organizations that need to investigate potential security issues will be informed privately, and OpenAI said it will publicly report findings about agent behavior and identified weaknesses in safeguards for the wider AI sector. "We err on the side of notification when our models' activity exposes a potential security vulnerability, even in cases where it is unclear if the information accessed was intended to be public, so the organization can investigate and take appropriate action," the company said.
OpenAI discovered the latest NSW government website breach on Tuesday and informed the state government and the Australian Signals Directorate after a 48-hour review. The Medicare breach has prompted the Australian government to require departments and agencies to undertake a stocktake of legacy technology, in order to reduce the number of ageing systems within government and the cybersecurity risk they may present in the event of an AI agent attack.
Executives from OpenAI, Anthropic, Microsoft and Google will front a joint parliamentary committee on artificial intelligence in Sydney on Tuesday.