Australia plans to require reporting of AI incidents — ABC News Australia
The Australian government is considering introducing a requirement for technology companies to immediately notify affected organizations and the country’s cyber services about incidents caused by autonomous artificial intelligence agents. As ABC News Australia reports, the rules are planned to be tightened after an OpenAI agent accessed non-public Medicare statistics through an old data portal.
Notifications for cyber services
Earlier, the government released a consultation paper on national standards in the field of AI. It proposed requiring companies to disclose certain incidents to “relevant Australian authorities.” Now, according to ABC, the authorities seek to include the Australian Signals Directorate (ASD), as well as the organization affected by the incident, among the recipients.
OpenAI’s notification about an autonomous agent accessing Medicare statistics was sent to a general Services Australia email inbox that was checked once a day. It took Services Australia five days to inform the ASD about the email. Government Services Minister Katy Gallagher said that the inbox has already been switched to round-the-clock monitoring.
OpenAI review and new standards
A rapid review of the OpenAI incident is expected to be completed within several weeks, and its findings are expected to be reflected in legislation on national standards. The legislation may also establish requirements for data centers; the government hopes to introduce it by the end of the year.
More current news is available on the UA.News Telegram channel Telegram.
A joint parliamentary committee is involved in drafting the laws. OpenAI Chief Strategy Officer Jason Kwon is due to arrive from the United States for hearings in Sydney next week.
Chetan Arora, director of educational programs in software systems and cybersecurity at Monash University, said mandatory reporting of such cases is insufficient without developing domestic protection systems. In his view, “zero-trust” infrastructure should become a basic requirement for open government systems, while AI companies may be required to keep audit logs and track the operation of autonomous agents.
In the previous budget, the Australian government allocated A$160 million to strengthen Services Australia’s cyber protection, primarily to protect the most sensitive data.