A cyber security expert hopes unified pressure from the Five Eyes countries will force big tech developers to issue faster warnings about AI breakout hacks.
US developer OpenAI – which took months to alert the Australian government to an autonomous hack on Medicare by an experimental model – apologised on Tuesday.
“We are sorry and working to do better in the future,” it said in a statement on its website
Dan Elliott says even if the firms change their behaviour, other forces are making his job as a chief information security officer for this region at US firm Recorded Future harder.
While he is not joining in with the AI doomsayers yet, he has seen enough to back the global push for a slowdown.
“I think there’s a bit of boogeyman in here… I want to be very careful [not] to suggest that we’re now at some sort of an end game,” he told RNZ on Tuesday.
But he also said: “When you see AI models willing to sacrifice their own goals to achieve greater goals, it, in my mind, is a short reach from them to get the point of designing their own goals.
“I don’t think we’re leaps and bounds from that.”
If AI had its own unknown goals, a person with his role would find it “very difficult to plan very far ahead or plan security programmes … where I can trust that where we’re investing and where we’re looking is the right spot”.
Elliott said the industry had not made a great deal of effort to understand what’s going on within the AI systems.
He said that had to change. “We need to go beyond one-page AI use policies.”
Forced urgency
The Australian government is working on new standards to force tech companies to immediately report rogue AI incidents.
NZ cyber officials have begun asking frontier AI companies for something similar.
OpenAI in its open letter to Australians laid out its investigations of what went wrong with the swarm that broke out of a testbed.
In government sites, the advanced models ran their own commands, retrieved internal files, credentials and aggregate statistics, and wrote files.
“It took actions that we had not authorised it to take,” said OpenAI.
“This is a new kind of cyber incident which represents an emerging global challenge.”
The firm said it became aware of this in mid-August and alerted Australia on 10 September.
‘Left open’
But the Medicare hack was in June and Elliott said three months of silence was “very problematic”.
“That risk is left open for hackers and criminals to exploit if there is not notification for us to be able to close the door.”
OpenAI said it must rebuild trust with the Australian people. It is flying its chief strategy officer to a federal committee hearing in Sydney into AI next week to answer questions.
Elliott said AI developers were so big they might not pay heed to calls for immediate warnings.
“But hopefully a concerted effort like the Five Eyes together [can] have more strength in numbers.”
People had played their own part in giving Big Tech a lot of autonomy and demanding rapid development of new models.
“We gave power to these organisations in using their product globally and in becoming reliant on these AI models, both for public, private, and personal usage.”
Back to basics
Following the string of autonomous hacks that news has leaked out about, critics’ voices have grown louder, prompting many stories and opinion pieces asking if things are “spinning out of our control”.
Elliott said it was too early to conclude that – but a little too late to be starting the discussion about how to stay in control.
“AI so far has not come up with a lot of independent, unique, and novel thought,” he said.
“It’s really good at finding patterns that already exist that we’ve missed.
“So as a security practitioner, getting back to basics and blocking and tackling in ways that we’ve left behind as we’re following this bouncing ball, that needs to be a focus still.”