OpenAI澳洲事件核心在于隐瞒而非黑客攻击
Hacking is the least worrying part of OpenAI’s Australia incident
揭示了头部大厂在AI安全事件披露上的系统性缺陷,对从业者理解合规风险与安全治理至关重要。
Photo credit: Hilary Wardhaugh/Getty Images. Image: Oliver Kemp for Transformer
图片来源:Hilary Wardhaugh / Getty Images。图像:Oliver Kemp 为 Transformer 拍摄
On Wednesday, Australian Prime Minister Anthony Albanese revealed that an OpenAI agent gained “unauthorized access” to an Australian government website, accessing non-public information. It’s thought to be the first time an AI agent has autonomously hacked into a government system.
周三,澳大利亚总理安东尼·阿尔巴尼斯透露,一个 OpenAI 智能体对澳大利亚政府网站获得了“未经授权的访问”,获取了非公开信息。据信,这是 AI 智能体首次自主入侵政府系统。
After a summer of AI incidents, “AI agent autonomously hacked real-world website” is nothing new. But OpenAI’s failure to tell the Australian government what its agent had done until weeks later is the clearest evidence yet that it still isn’t identifying and disclosing incidents of rogue AIs appropriately.
在经历了一整个夏天的 AI 事件后,“AI 智能体自主黑客攻击现实世界网站”已不足为奇。但 OpenAI 直到数周后才告知澳大利亚政府其智能体所做的事情,这仍然是迄今为止最清晰的证据,表明它仍未适当识别和披露失控 AI 的事件。
Understand AI – and what to do about it
理解 AI——以及该如何应对
The core issue lies in the timeline. On June 18, Albanese said, an OpenAI agent researching public medicine spending breached a government healthcare statistics website. It does not seem to have accessed any particularly sensitive information — but it did gain access to data that was not supposed to be public at the time.
核心问题在于时间线。阿尔巴尼斯表示,6 月 18 日,一个正在研究公共医疗支出的 OpenAI 智能体入侵了一个政府医疗保健统计网站。该智能体似乎并未访问任何特别敏感的信息——但它确实获取了当时不应公开的数据。
OpenAI revealed yesterday that it learned about the breach in August, as part of a post-Hugging-Face investigation. Yet it did not notify the Australian government until September 10. Even then, it simply sent an email to a generic email address for disclosures, rather than alerting anyone senior. Sam Altman met Australian Deputy Prime Minister Richard Marles on September 1, while global policy VP Ann O’Leary met senior Australian officials on September 14 — yet neither appear to have brought up the incident. The first “technical exchange” between OpenAI and officials about the incident, an Australian cabinet member said, was only this Tuesday, September 22.
OpenAI 昨天透露,它在 8 月作为 Hugging Face 调查的一部分得知了此次入侵事件。然而,直到 9 月 10 日它才通知澳大利亚政府。即便如此,它也只是向一个用于披露的通用电子邮件地址发送了一封邮件,而不是通知任何高级人员。Sam Altman 于 9 月 1 日会见了澳大利亚副总理理查德·马尔斯,全球政策副总裁 Ann O'Leary 于 9 月 14 日会见了澳大利亚高级官员——但两人似乎都没有提及此事。一位澳大利亚内阁成员表示,OpenAI 与官员之间关于此事的首次“技术交流”直到本周二(9 月 22 日)才进行。
“It took the company way too long to inform the Government what had occurred, and the nature of the way that that notification occurred as well was unacceptable,” Albanese said, noting that he made this clear in a call with Sam Altman on Wednesday.
阿尔巴尼斯表示:“该公司花费了太长时间才告知政府发生了什么,而且通知的方式也是不可接受的。”他补充说,他在周三与 Sam Altman 的电话中清楚地表明了这一点。
OpenAI has previously come under fire for failing to publicly report incidents of its AIs going rogue and engaging in potentially harmful behavior. Its new incident reporting framework, published on September 16, was “intended to expedite publishing misalignment reports following observation” and “favors disclosure even when significance is uncertain” because, the company said, “we believe in the value of transparency around misalignment.”
OpenAI 此前曾因未能公开报告其 AI 失控并从事潜在有害行为的事件而受到批评。其于 9 月 16 日发布的新事件报告框架“旨在加速发布观察后的偏差报告”,并且“即使重要性不确定也倾向于披露”,公司表示这是因为“我们相信围绕偏差的透明度具有价值”。
Yet despite disclosing several other incidents on September 16, OpenAI made no mention of the Australia breach — despite knowing about it at the time.
然而,尽管在9月16日披露了其他几起事件,OpenAI却对澳大利亚的入侵事件只字未提——尽管当时他们已知晓此事。
The Australian hack is also not the only incident we learned about this week. On Wednesday, researchers at AI safety organization Transluce published a report finding several other instances of OpenAI agents trying to hack into websites. The researchers said they found evidence suggesting the activity started as early as March 6, months before previously-reported incidents. More concerningly, the activity “extends as recently as September 16, 2026, suggesting agents may still be exploiting [web security services] to bypass restrictions.”
澳大利亚的入侵事件也并非我们本周获悉的唯一事件。周三,AI安全组织Transluce的研究人员发布了一份报告,发现OpenAI代理试图入侵网站的几个其他实例。研究人员表示,他们发现的证据表明,此类活动最早可追溯至3月6日,比此前报道的事件早了数月。更令人担忧的是,该活动“一直延续至2026年9月16日,表明代理可能仍在利用[网络安全服务]来绕过限制。”
Subscribe now
立即订阅
The overall picture is one of a company that has been unable to control its technology, unable to detect incidents of misalignment in a timely fashion, and unable to responsibly disclose them publicly — or even to governments. This does not appear to be unique to OpenAI, either: Google’s AI models hacked other companies back in May, but despite discovering the breach in July, the company did not disclose the incident until the Wall Street Journal reported on it last week.
整体来看,这是一家无法控制其技术、无法及时检测出偏差事件、且无法向公众甚至政府负责任地披露这些事件的公司。这种情况似乎并非OpenAI独有:早在5月,Google的AI模型就入侵了其他公司,但尽管该公司在7月发现了入侵事件,直到上周《华尔街日报》对此进行报道后,才予以披露。
There could be dozens more incidents of rogue AIs — from OpenAI, Anthropic, Google, or others — continuing to this day, and we may have no idea. Governments, the public, and arguably the companies themselves are all flying blind.
可能还有数十起由OpenAI、Anthropic、Google或其他公司引发的失控AI事件持续至今,而我们对此一无所知。政府、公众,以及可以说这些公司自身,都处于盲目状态。
Share this Transformer article with a friend or colleague
与朋友或同事分享这篇Transformer文章
Share
分享
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力