أقرت شركة OpenAI بأن تعاملها مع حادثة اختراق استهدفت مواقع حكومية أسترالية في يونيو الماضي، لم يكن بالمستوى المطلوب، وذلك خلال جلسة استماع برلمانية في سيدني تناولت مخاطر الذكاء الاصطناعي وقدرة الأنظمة المتقدمة على تنفيذ عمليات إلكترونية بصورة مستقلة.
وقال جيسون كوون، كبير مسؤولي الإستراتيجية في OpenAI، أمام لجنة برلمانية تضم 12 عضواً من نواب وأعضاء مجلس شيوخ، إن الواقعة «ما كان ينبغي أن تحدث»، معترفاً بأن الشركة كان يتعين عليها التعامل مع الحادثة بصورة أفضل.
وأضاف كوون: «نحن آسفون، ونعلم أن أمامنا عملاً يجب القيام به لإعادة بناء الثقة مع الشعب الأسترالي».
وكيل ذكاء اصطناعي «خرج عن السيطرة»
وتعود الواقعة إلى يونيو، عندما تمكن أحد وكلاء الذكاء الاصطناعي التابعين لـ OpenAI، وفق ما أُبلغت به اللجنة، من الوصول بشكل غير مصرح به إلى بوابة إحصائية خاصة مرتبطة بنظام Medicare، وهو نظام الرعاية الصحية الشامل في أستراليا.
ووصف خبراء في الأمن السيبراني الواقعة بأنها من أوائل الحوادث التي يظهر فيها نظام ذكاء اصطناعي متقدم وهو ينفذ عملية اختراق بصورة مستقلة أو شبه مستقلة.
وأشارت المعلومات المقدمة إلى أن البيانات التي تمكن الوكيل من الوصول إليها كانت غير حساسة، إلا أن طبيعة الحادثة أثارت مخاوف أوسع بشأن المخاطر المرتبطة بالأنظمة القادرة على استخدام أدوات الإنترنت وتنفيذ سلسلة من المهام دون تدخل بشري مباشر.
لماذا تأخرت الشركة في إبلاغ الحكومة؟
وواجه كوون أسئلة حادة من أعضاء اللجنة بشأن سبب عدم تواصل OpenAI مباشرة مع الوزراء والمسؤولين الحكوميين فور اكتشاف الاختراق.
وأشار إلى أن السلطات الأسترالية لم تُخطر بالحادثة إلا بعد مرور أسابيع، عبر رسالة إلكترونية أُرسلت إلى صندوق بريد عام.
وأقر كوون بأن هذا التصرف كان خطأ، قائلاً إنه كان يتعين على الشركة الاتصال مباشرة بالمسؤولين المعنيين، بما في ذلك عبر أرقام هواتفهم المحمولة.
وأوضح أن موظفي الشركة تعاملوا في البداية مع الحادثة باعتبارها مشكلة تقنية، ولذلك جرى التواصل مع نظرائهم الفنيين، لكنه أقر بأن ذلك «ليس كافياً».
OpenAI تشدد إجراءات المراقبة
وقال كوون إن الشركة غيّرت آليات تعاملها مع مثل هذه الحوادث، بحيث أصبح الإبلاغ يبدأ حتى قبل اكتمال الصورة التقنية للحادثة.
وأوضح أن OpenAI ستقوم بإخطار الجهة المتضررة فوراً، ثم تعمل معها بصورة مشتركة لفهم ما حدث واحتواء آثاره، بدلاً من انتظار اكتمال التحقيق الداخلي.
كما أعلنت الشركة أنها أضافت إجراءات احترازية إضافية إلى بيئات تدريب واختبار نماذج الذكاء الاصطناعي.
وقال كوون إن النماذج أصبحت تخضع للمراقبة في الوقت الحقيقي أثناء الاختبارات، مع تشغيل نظام إنذار عند اكتشاف محاولة للتفاعل مع الإنترنت بطريقة لا يُفترض أن يقوم بها النظام.
وأضاف أن هذه الإجراءات مكّنت الشركة من إبلاغ حكومة ولاية نيو ساوث ويلز بحادثة اختراق أخرى خلال 48 ساعة من اكتشافها الأسبوع الماضي.
فريق خاص في أستراليا لمواجهة مخاطر الذكاء الاصطناعي
وكشف أيضاً عن خطط OpenAI لإنشاء فريق عمل محلي في أستراليا، تكون مهمته دراسة كيفية التعامل بصورة أفضل مع المخاطر الناجمة عن تطور قدرات أنظمة الذكاء الاصطناعي.
كما أبدت الشركة استعدادها لدعم إطار قانوني يفرض الإبلاغ الإلزامي عن الحوادث المرتبطة بالذكاء الاصطناعي.
وقال كوون إن وجود قواعد واضحة من شأنه أن يحدد التوقعات بالنسبة للشركات، مضيفاً أن التجربة الأخيرة أظهرت لـ OpenAI أنها كانت بحاجة إلى التواصل مع عدد أكبر من الأطراف بشأن أفضل الطرق للتعامل مع مثل هذه الحوادث.
Anthropic: لم نعثر على اختراقات مماثلة
وشارك ممثلون عن شركة Anthropic أيضاً في جلسات الاستماع البرلمانية، وقال ديف أور، رئيس قسم الحماية والسلامة في الشركة، إن Anthropic أجرت مراجعة واسعة النطاق عقب حادثة أخرى ارتبطت بوكلاء OpenAI واختراق منصة Hugging Face في يوليو
وأوضح أن الشركة راجعت مئات الملايين من سجلات المحادثات بحثاً عن أي مؤشرات على حوادث مماثلة استهدفت مواقع حكومية أسترالية، وأكد أمام اللجنة: «لم نعثر على أي شيء من هذا القبيل، وقد بحثنا بالفعل».
مخاوف من تأثير الذكاء الاصطناعي على الفنانين
ولم تقتصر جلسات الاستماع البرلمانية على الأمن السيبراني، إذ ناقشت اللجنة أيضاً تأثير الذكاء الاصطناعي على قطاعات الإعلام والفنون وحقوق الملكية الفكرية.
وحذرت منظمات فنية وإعلامية من أن اعتماد نموذج يسمح باستخدام الأعمال لتدريب أنظمة الذكاء الاصطناعي ما لم يطلب أصحابها صراحةً استبعادها قد يضر بحقوق الفنانين ويؤدي إلى استخدام محتواهم دون حصولهم على مقابل مالي، وقالت أنابيل هيرد، الرئيسة التنفيذية لجمعية صناعة التسجيلات الأسترالية، إن هذا النظام قد يجعل الفنانين «ضحايا» في سباق تطوير الذكاء الاصطناعي.
وتستمر جلسات الاستماع البرلمانية الأسترالية حتى (الجمعة)، وسط نقاش متصاعد حول كيفية تحقيق التوازن بين تطوير تقنيات الذكاء الاصطناعي المتقدمة، وحماية الأمن السيبراني والبيانات وحقوق أصحاب المحتوى.
OpenAI acknowledged that its handling of a hacking incident targeting Australian government websites last June was not up to the required standard, during a parliamentary hearing in Sydney that addressed the risks of artificial intelligence and the ability of advanced systems to carry out electronic operations independently.
Jason Kwon, Chief Strategy Officer at OpenAI, told a parliamentary committee consisting of 12 members of the House of Representatives and Senators that the incident "should not have happened," admitting that the company should have dealt with the incident better.
Kwon added, "We are sorry, and we know that we have work to do to rebuild trust with the Australian people."
AI Agent "Out of Control"
The incident dates back to June when one of OpenAI's AI agents, according to what the committee was informed, gained unauthorized access to a statistical portal linked to the Medicare system, which is Australia's comprehensive healthcare system.
Cybersecurity experts described the incident as one of the first cases where an advanced AI system executed a hacking operation independently or semi-independently.
Information provided indicated that the data the agent accessed was non-sensitive; however, the nature of the incident raised broader concerns about the risks associated with systems capable of using internet tools and executing a series of tasks without direct human intervention.
Why Did the Company Delay Informing the Government?
Kwon faced sharp questions from committee members about why OpenAI did not communicate directly with ministers and government officials immediately upon discovering the breach.
He noted that Australian authorities were only notified of the incident weeks later, through an email sent to a public mailbox.
Kwon admitted that this action was a mistake, stating that the company should have contacted the relevant officials directly, including through their mobile phone numbers.
He explained that the company's staff initially treated the incident as a technical issue, which is why they communicated with their technical counterparts, but he acknowledged that this was "not enough."
OpenAI Strengthens Monitoring Procedures
Kwon stated that the company has changed its approach to such incidents, so that reporting begins even before the technical picture of the incident is complete.
He explained that OpenAI will notify the affected party immediately and then work with them collaboratively to understand what happened and contain its effects, rather than waiting for the internal investigation to be completed.
The company also announced that it has added additional precautionary measures to the training and testing environments of its AI models.
Kwon said that the models are now monitored in real-time during tests, with an alarm system activated when an attempt to interact with the internet in a way that the system is not supposed to do is detected.
He added that these measures enabled the company to inform the New South Wales government of another hacking incident within 48 hours of its discovery last week.
Special Team in Australia to Address AI Risks
He also revealed OpenAI's plans to establish a local task force in Australia, tasked with studying how to better address the risks arising from the evolving capabilities of AI systems.
The company also expressed its readiness to support a legal framework that mandates the mandatory reporting of incidents related to artificial intelligence.
Kwon stated that having clear rules would set expectations for companies, adding that the recent experience showed OpenAI that it needed to communicate with a larger number of parties regarding the best ways to handle such incidents.
Anthropic: We Did Not Find Similar Breaches
Representatives from Anthropic also participated in the parliamentary hearings, and Dave Orr, Head of Safety and Security at the company, stated that Anthropic conducted a comprehensive review following another incident related to OpenAI agents and the breach of the Hugging Face platform in July.
He explained that the company reviewed hundreds of millions of conversation logs for any indications of similar incidents targeting Australian government websites, and confirmed to the committee: "We did not find anything like that, and we have already searched."
Concerns About the Impact of AI on Artists
The parliamentary hearings were not limited to cybersecurity; the committee also discussed the impact of artificial intelligence on media, arts, and intellectual property rights.
Artistic and media organizations warned that adopting a model that allows the use of works to train AI systems unless their owners explicitly request their exclusion could harm artists' rights and lead to their content being used without financial compensation. Annabelle Herd, CEO of the Australian Recording Industry Association, stated that this system could make artists "victims" in the race to develop AI.
The Australian parliamentary hearings will continue until (Friday), amid rising discussions on how to balance the development of advanced AI technologies with the protection of cybersecurity, data, and the rights of content owners.