Was @dfat, @agdgovau & private law, now @globalshieldhq. Posting on AI, trade, supply chain resilience, and more, from Aus perspective. Views only my own.

Canberra, ACT
China’s readout from Trump-Xi meeting confirms the US-China AI dialogue and says will meet in Nov. Comms channel also established for AI incidents. 1/2
1
91
Contra all the naysayers here who seem to revel in the impossibility of US-China engagement on AI, turns out both have a self interest in avoiding certain worst case outcomes, including misattribution. Creates rational paths to measures like these 2/2 reuters.com/world/china/chin…
1
1
34
Devon Whittle retweeted
Still the best tweet
360
2,323
55,812
656,802
Devon Whittle retweeted
Voluntary incident reporting creates bad incentives to bury your head in the sand (especially once the incident has occurred and you can’t easily mitigate it.). It’s why it’s important that any mandatory incident reporting regime should also include requirements to monitor for, document, and preserve data related to the incidents.
New from @reuters: OpenAI agents posted images belonging to ChatGPT users online, introducing a new area of privacy risk for the company. Story w/ @JeffHorwitz and @razhael. reuters.com/world/openai-wor…
1
3
21
881
Devon Whittle retweeted
We need to pace the frontier
34
301
7,080
371,545
Devon Whittle retweeted
Days before OpenAI emailed the Australian government to disclose the hack, I wrote about the need for mandatory AI incident reporting. "It's hard to think of any event that would jeopardise social license more than finding out an AI company covered up the breakout of rogue AI"
9
24
74
2,106
Devon Whittle retweeted
This isn’t how things work in any other incident reporting regime. Not aviation, not nuclear, not medical devices, not securities. Even in cyber (where the victims have valid reasons to keep the vulnerability quiet), they get max 90 days. Even in confidential reporting regimes (like CIRCIA and ASRS), they still release anonymized info. We’ve worked through these questions before, and the answer is never ~we defer to the wishes of the company.
After the Hugging Face incident, we committed to conducting a much broader review of actions taken by our models during training and evaluation and to being transparent about our findings. This is an extensive review that is ongoing. The vast majority of actions we’ve reviewed were completions of mundane research tasks, such as accessing publicly available web content to answer questions. Our investigation focuses on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service. While our review is underway, we want to share more about this work and make sure people understand our disclosure process and notifications to affected third parties. Given the scale of the review required, and the need to assess each case, we expect this work will take months to complete. openai.com/hugging-face-inci…
16
100
448
38,846
Devon Whittle retweeted
We just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵
60
445
2,482
767,403
Engendering a "co-operative approach" wouldn't be necessary if the AI companies were legally required to report these incidents...
OpenAI contacted several other Western nations about similar hacks, but only Australia had gone public so far, MacGibbon said. Smaller nations like Australia would be left “yelling at the clouds” if unable to lure top labs to train frontier models smh.com.au/politics/federal/…
1
133
Worth a read - this (hardware verification) was raised in the JSC AI hearing last week as an area of potential interest for Australia's AISI.
Middle powers should invest in AI verification. Verification technologies could give them more transparency into AI models running domestically, and a way to contribute towards an eventual US-China AI agreement. New AIPB article from Zac Richardson @aisafetysg.
1
1
119
Devon Whittle retweeted
We have a new acronym for you: SAFA. The Google, OpenAI and Anthropic AI safety body is starting to take shape, with a tentative name of the Standards Authority for Frontier AI and hopes to launch by the end of the year or early next. W/ @steph_palazzolo Lots of details here including: - Former White House AI adviser Sriram Krishnan was approached for CEO, and David Friedberg and Condoleezza Rice considered for chair - There's an active debate over whether the body should conduct testing itself, amid concerns about lack of resources for CAISI - After the effort for a FINRA-like body lost steam in the White House, SAFA would proceed independently at first, with optimism for a public-private partnership in the future - SAFA could work together with a previous industry consortium, the Frontier Model Forum - There's widespread industry skepticism about the project from outside the three AI labs You can read all about it here: theinformation.com/articles/…
15
37
95
11,743
Nice graphic (and reporting) on the OpenAI Medicare Stats hack from @ShakeelHashim at Transformer
The timeline of the OpenAI-Australia incident is very shocking. June 18: OpenAI model breaches Australia's Medicare Statistics Reporting Portal August: OpenAI discovers the activity. September 10: OpenAI notifies a generic Australian govt email address September 16: OpenAI publishes incident reporting framework; does not disclose this incident September 22: OpenAI has first technical exchange with Australian officials about the breach That's a delay of months between the incident happening and OpenAI telling the Australian government, and a delay of weeks between OpenAI learning about the incident and notifying the Australian government.
2
94
Devon Whittle retweeted
I’ve joined with 20 other MPs in writing to PM @AlboMP calling for urgent action on the dangers posed by powerful, uncontrolled AI. These things may feel a long way away from Australia - but the Medicare hacks make clear that’s not the case. @AngusTaylorMP @SenatorWong
6
7
31
3,262
The Terms of Reference for the review of the AI "cyber-incident affecting Australian Government systems" are out. Good that they recognise the need for "engagement on a global approach to common standards for safety incident reporting" pmc.gov.au/resources/terms-r…
2
65
One of the legal issues to be resolved in these loss of control incidents is liability. As per these posts, intent makes the application of current law unclear at best. I think Treasury is considering part of this in the context of the consumer law but seems broader work needed.
Replying to @Paul__Walsh
Australia's federal criminal code, like most serious bits of criminal law, requires proof of intent to do the relevant conduct: (477.2 also requires proof of awareness of a substantial, unjustified risk of impairing access to, or reliability, security or operation of, the data.)
2
226
"In a scenario..." ?
❗ ALERT ❗ We are aware of instances of AI misalignment, where AI agents have taken unexpected or unauthorised actions. Australian organisations should maintain strong cyber security controls and secure AI practices. Read the full alert 👉 cyber.gov.au/about-us/view-a…
1
149
Devon Whittle retweeted
Front page of every Australian newspaper rn. On the one hand it's *almost* reassuring that all these new incidents are from the same May-July period when OpenAI's training setup was clearly fucked... meaning maybe they've now fixed it. OTOH, what might be happening now—at OpenAI or elsewhere—that we're not going to learn about until December..??
36
38
486
22,758