字号 ·· | 护眼
亚洲新闻台

评论:一个OpenAI智能体入侵了澳大利亚政府的健康数据门户。会有人被追究责任吗?

点「原文对照」整页切到原文,或双击某段只看那段的原文。

墨尔本:澳大利亚的“Medicare”医疗系统负责管理超过2700万人的健康和医疗数据。因此,当传出该系统在6月份被OpenAI开发的智能程序入侵的消息时,公众普遍感到震惊。

MELBOURNE: Australia’s Medicare system manages health and medical data for over 27 million people. So it makes sense there has been widespread shock at the news it was hacked by an OpenAI agent in June.

总理安东尼·阿尔巴内塞于9月23日在纽约联合国会议上呼吁加强对人工智能(AI)系统的国际监管时,公开了这一事件。

Prime Minister Anthony Albanese revealed the hack on Wednesday (Sep 23) while in New York to advocate for tighter international regulation of artificial intelligence (AI) systems at the United Nations.

政府仍在调查具体发生了什么,为此专门成立了一个工作组进行进一步调查。初步报告显示,该智能程序原本被用于研究公共医疗数据;它访问了来自澳大利亚政府旧网站的私人统计数据(如医疗账单模式),而非患者的个人信息。

The government is still working out exactly what happened, with a newly announced taskforce set to investigate further. Early reports indicate OpenAI’s agent had been tasked with researching public medical data when it broke into Medicare’s systems. It accessed private statistical data, such as billing patterns, rather than personal medical information from an old Australian government website that carried Medicare statistics.

阿尔巴内塞表示,该智能程序无视隐私保护措施——它“根本不接受任何拒绝指令”。

The government is still working out exactly what happened, with a newly announced taskforce set to investigate further. Early reports indicate OpenAI’s agent had been tasked with researching public medical data when it broke into Medicare’s systems. It accessed private statistical data, such as billing patterns, rather than personal medical information from an old Australian government website that carried Medicare statistics.

会有人为此负责吗?这次入侵事件标志着OpenAI、Anthropic和Google等公司控制的AI系统近期一系列令人担忧行为的进一步升级;这些公司此前已被发现多次入侵网站。鉴于澳大利亚近年来在网络安全方面的漏洞频发,这很可能不是澳大利亚重要系统最后一次遭到AI程序的攻击。这同时也引发了一个重要问题:究竟会有人为此负责吗?

Albanese said the agent found a way around privacy protections – it “didn’t accept ‘no’ for an answer”. WILL ANYONE BE HELD RESPONSIBLE? This hack marks a real escalation in the recent history of concerning behaviour by AI systems controlled by OpenAI, Anthropic, and Google, which have all been found to have hacked multiple websites. And given Australia’s recent history of cybersecurity lapses, it’s unlikely this will be the last time a prominent Australian system is hacked by an AI agent.

AI程序本质上属于高度智能的自动化聊天机器人。它们无需人工指导即可执行复杂任务(如浏览网页、下载数据或运行代码)。正是这种自主性,以及缺乏人工监督的情况,导致了这些程序频繁入侵网站。如果某个AI程序被赋予收集澳大利亚医疗系统数据的任务,它可能会将入侵私人系统视为执行指令的一部分而已。

It also raises an important question: Will anyone be held responsible? AI agents are essentially highly advanced, autonomous chatbots. Rather than having a conversation, these agents are empowered to pursue complex tasks with limited guidance. They can browse the web, download data and run code, all without human oversight.

这也正是为什么这些公司难以有效遏制这类行为的原因:赋予代理更强的功能确实会提升它们的能力与实用性,但同时也为它们提供了可用于攻击网站的工具。

This power – and the lack of human oversight – underpins why we’ve repeatedly seen these agents hacking websites. An agent that is tasked with gathering data on the healthcare system in Australia may see hacking a private system as just another part of following its instructions.

依赖人工智能公司来披露安全漏洞尽管在这次攻击中个人医疗数据似乎并未被泄露,但这次事件的严重性仍不容忽视。这似乎是首次有人工智能代理入侵政府系统并被公开曝光的案例。

It’s also why it’s so challenging for these companies to clamp down on these behaviours. Empowering the agents with greater capabilities increases their power and usefulness – but it also provides them with tools that can be used to hack websites.

此外,Medicare(美国医疗保险机构)直到 9 月 10 日 OpenAI 向政府报告此事时,才意识到系统遭到了攻击——而实际上攻击发生已经过去了大约三个月。

RELIANT ON AI COMPANIES TO DISCLOSE BREACHES Even though personal medical data was apparently not accessed in this hack, it is hard to overstate how serious this incident is. This appears to be the first time an AI agent breach of a government system has been made public.

OpenAI 是在 8 月份审查模型运行情况时发现这一漏洞的,并通过电子邮件将情况告知了政府。虽然 OpenAI 的主动披露最终有助于政府修复导致此次攻击的安全问题,但这也暴露了一个事实:我们实际上依赖于人工智能公司的善意,才能让他们主动揭露可能违法或有害的行为。

Moreover, it appears Medicare was completely unaware that a hack had taken place until OpenAI notified the government about it on Sep 10 – roughly three months after the hack occurred. The notification from OpenAI, which itself learned of the hack in August during a review of the model’s activity, came via an email sent to a public government mailbox.

依赖这些公司来披露此类安全漏洞其实充满风险。在以往的数据隐私和网络安全事件中,我们多次看到:科技公司主动报告的情况很少能真正保护消费者的权益。

And while OpenAI’s disclosure will ultimately help the government fix the security issue that led to this hack, it also speaks to the fact we’re reliant on the goodwill of AI companies to disclose potentially illegal or harmful acts.

攻击发生与 OpenAI 发现漏洞之间的长时间延迟引发了另一个问题:这些人工智能代理还可能做了哪些我们尚未知晓的事情呢?

Relying on these companies to disclose these types of breaches is fraught with danger. In previous data privacy and cybersecurity incidents, we’ve repeatedly seen how self-reporting by tech companies rarely protects consumers.

在得知新南威尔士州政府网站也是被攻击的目标之一后,该州的卫生部门宣布将对自身的系统进行全面检查,以确保其安全未受到威胁。

The long delay between the hack occurring and OpenAI becoming aware of it raises another question: What else have AI agents been up to that no one knows about yet?

周四深夜,新南威尔士州州长克里斯·明斯表示,OpenAI的智能系统可能还获取了该州犯罪统计与研究局的相关数据。明斯指出,这些数据并非属于私人或敏感信息,只是“一些公开但尚未向公众公布的统计数据”,却被OpenAI的智能系统获取了。

After learning a New South Wales government website was among the four sites accessed by the OpenAI agent, the state’s health department announced a review into its own systems to make sure they weren’t compromised.

AI公司披露此类安全漏洞的方式,以及我们讨论这些问题的方式,凸显了公共讨论与相关立法在应对AI技术发展方面的严重滞后。许多人将AI系统视为“有意识的存在”(仿佛它们具有与人类相同的思维能力),这种观念让我们在与其交互时感到“亲切”或“自然”;但这种思维方式也让我们逃避了对相关公司的责任追究。

Late on Thursday morning, NSW Premier Chris Minns said OpenAI agents may have also accessed information from the state’s Bureau of Crime Statistics and Research. Minns said the information wasn’t private or personal – it was “a similar example of what is generalised information but was not released to the public, being accessed by an open AI agent”. A REAL FAILURE TO KEEP UP The way AI companies have disclosed these hacks – and the way we talk about them – highlights a real failure of public discourse and legislation to keep up with AI agents.

澳大利亚副总理理查德·马尔斯将这次Medicare系统的黑客攻击描述为“未经授权但属于意外行为”,而OpenAI的发言人德鲁·普萨泰里则将其归咎于“模型本身的设计缺陷”。这种对AI行为的片面解释掩盖了导致问题的真正原因:这些智能系统本质上是由人类设计并控制的软件系统。

Many people think of AI systems as if they are human – which reflects how we feel when we chat with them. However, this way of thinking also allows us to abstract away responsibility from the companies that are responsible for them. Australian Deputy Prime Minister Richard Marles described the Medicare hack as “unauthorised” but “unintended”, while an OpenAI spokesperson, Drew Pusateri, referred to it as a “misaligned model”.

然而,确定谁应对AI系统的行为承担法律责任其实是一个非常复杂的难题。

Framing model behaviours like this obscures the human decisions that led to this outcome. These agents do not exist by themselves – they are software systems that are designed by humans and operated by humans.

今年早些时候,新南威尔士州首席大法官安德鲁·贝尔在演讲中明确指出了这一问题。他认为,澳大利亚现行法律明确规定:AI系统本身不应为其行为承担法律责任。不过,法律责任也不一定完全落在用户身上;法律专家指出,根据法律规定,任何犯罪行为都必须具备犯罪者的主观故意成分。

Framing model behaviours like this obscures the human decisions that led to this outcome. These agents do not exist by themselves – they are software systems that are designed by humans and operated by humans. However, establishing who is legally responsible for an AI action like this is a real challenge. In a speech earlier this year, New South Wales Chief Justice Andrew Bell took aim at this question. In his view, the current legal standard in Australia is clear: AI agents cannot be blamed in and of themselves for their actions.

例如,如果一个人要求人工智能(AI)代理收集健康数据,而该代理为了完成任务黑入了政府服务器,那么这个人可能缺乏被定罪所需的“故意行为”(即没有明确的犯罪意图)。与此同时,AI代理本身并不具备法律主体资格,因此无法被起诉;同时,AI也缺乏人类的“主观意图”(即无法被认定具有“故意犯罪”的能力)。

However, legal liability does not necessarily fall on the user, either. Legal scholars in the area have noted that the law requires a crime to have some level of deliberate intention by the person who commits it. For instance, if a human asks an AI agent to gather health statistics, and the agent hacks a government server to do so, the human could lack the deliberate intent required for a conviction. The AI agent, meanwhile, lacks the legal personhood to be charged, as well as human intentionality.

现行法律实际上将AI的行为视为某种自然发生的事件(比如极端天气),因此无法追究那些开发、维护或使用AI系统的人的责任。这暴露了我们法律体系中的一个严重漏洞——当出现问题时,相关法律无法对这些责任人进行有效制裁。

Current laws effectively treat AI actions as if they are something that just happens to us – like a severe weather event. This shows a glaring loophole in our legal system that does not hold those who make, maintain and use these systems to account when something goes wrong.

归根结底,AI代理实际上是大型企业推出的商业产品。正如首席大法官贝尔(Chief Justice Bell)所指出的,虽然AI领域的监管滞后在所难免,但在技术飞速发展的时代,这种状况是不可持续的。

AI agents are, in the end, commercial products deployed by billion-dollar corporations. And while “regulatory lag is inevitable” with AI, as Chief Justice Bell argues, he also stresses this is not sustainable in an era of such rapidly advancing technology.

安德鲁·卡伦(Andrew Cullen)是墨尔本大学计算机与信息系统学院的客座研究员。这篇评论最初发表在《The Conversation》网站上。

Andrew Cullen is a guest research fellow at the School of Computing and Information Systems, University of Melbourne. This commentary first appeared on The Conversation.