Labor to introduce AI standard bill by year’s end
Australian Environment Minister Murray Watt said Friday that the federal government would update Australian law if existing legislation cannot hold OpenAI accountable for the June hack of a Medicare statistics website by an AI agent developed by the company. The statement came as the government confirmed that a review by the Australian Signals Directorate would consider whether legislative change was needed.
The breach saw an artificial intelligence agent developed by OpenAI gain access to the Medicare statistics website and three other Australian government systems in June, according to a government statement on Friday.
Albanese rejected accusations from the opposition that he had delayed announcing the breach. “It’s just nonsense … I was informed while I’ve been in New York,” the prime minister told News24 on Friday.
The prime minister argued that releasing the information before the facts were confirmed would have caused unnecessary public alarm. “Imagine if we had said there’s been a data breach, but we don’t know what has been sourced, we don’t know if your personal information is out there, that would have created a great deal of anxiety, which was unnecessary,” Albanese said. “We had to ascertain the facts, and then we made the statements, as a matter of urgency, we also provided briefings to the opposition, as is appropriate.”
Government Services Minister Katy Gallagher was informed of the breach on September 17, and informed Albanese between Friday September 18 and Saturday September 19, according to Guardian Australia. Albanese left for the United States on the Friday, where he first met with Apple’s executive chairman Tim Cook in California on Saturday morning before flying to New York that afternoon.
Speaking to the Asia Society on Thursday, the prime minister described the incident as a “wake-up call” about the risks of artificial intelligence and about whether humans would remain in charge of the technology. “This technology is moving very, very fast, and we need to make sure that we have a responsibility to keep on top of it,” Albanese said.
Watt told Channel Seven’s Sunrise program that the government’s task force would examine whether the matter could be referred to the Australian Federal Police under current law. “There’s now a review of this underway through that task force that we’ve appointed, and one of the things that they’ll be looking at is whether these matters can be referred to the Australian federal police under current Australian law,” he said. “If that is possible to happen, then that will happen. If it’s not possible, then clearly that indicates that we need to change Australian laws, and that’s what we’ll be doing.”
Assistant Minister for Technology and the Digital Economy Andrew Charlton told ABC radio that similar incidents would become “more and more prevalent into the future” and that the government would need to be prepared. “That’s why we’re conducting a review of the incident as well as a review of the laws to determine exactly … whether there needs to be legislative change to recognise this type of incident conducted by an AI agent rather than directly by a person or a company,” Charlton said.
Labor has announced it would legislate an AI standard, which Charlton said would be informed by the rapid review. The government has said it wants the bill to be introduced by the end of the year.
UNSW professor Lyria Bennett Moses, an academic expert in technology and law, said Australia’s criminal laws should be clarified to determine how fault, such as intention or knowledge, is applied to a corporation when its AI agent commits a crime. She said existing laws are clear if a human or corporation gains unauthorised access to restricted data, but it is more complicated when an AI agent commits the physical element of the offence. “The person is not the AI agent, so it’s not about what the AI agent intended. It’s about how you attribute that intention and that knowledge back to a corporation,” she said.
Bennett Moses said existing civil laws are more likely to deal with these sorts of incidents, allowing a government or individual to seek compensation from an AI company for harm “negligently caused by that corporation.” “If their systems have suffered harm and there is financial loss, and that harm was caused by the negligence of a corporation, you’ve got a potential for litigation to get compensation for that harm,” she said. “Here it seems to me much easier to hold a company liable, because if a company caused the harm, it’s not a defence to say that my bot did it.”
Opposition Leader Angus Taylor told reporters the opposition would be open to working with the government to hold companies accountable. “I’ve long believed that data breaches need to be dealt with in an appropriate way and those responsible for the data breaches need to be accountable for it … But we’ll wait and see what the government has in mind,” Taylor said.
OpenAI spokesperson Drew Pusateri said Thursday the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems.” “During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” Pusateri said in a statement. Pusateri added that OpenAI was supporting investigations and committed to “sharing what we learn as that work continues.”