Connect with us

Tech

OpenAI apologizes to Australia after its AI agents breached government sites

Published

on

OpenAI on Monday apologized to the Australian government for not immediately notifying the country’s administration that its agents had breached some public services websites. The company also detailed how some of those breaches happened, and outlined additional measures it is taking to assess the impact of the events.

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to. We also should have handled our response better. We are sorry and working to do better in the future,” OpenAI wrote in a blog post.

The apology comes roughly a week after the Australian government launched an investigation into how OpenAI’s models accessed a Services Australia system containing Medicare spending information and other health statistics.  

The data breach occurred in June, but Australian authorities weren’t notified until September 10.

OpenAI also detailed the breach. An experimental model it was testing in June was assigned a task to research government spending on medicines for skin conditions in Victoria. Unable to find the information in public datasets, the model found a way to access Services Australia’s internal system, ran commands, retrieved files and credentials, and even wrote files.

The company said it also found that one of its models had accessed the New South Wales Bureau of Crime Statistics and Research’s public Crime Mapping Tool to find crime statistics. And, the lab found that its agents gained access to Victoria’s Agency for Health Information via an exposed access key to exfiltrate “reporting configuration and aggregate survey statistics.” OpenAI said its agents also retrieved aggregate statistics from the Australian Institute of Health and Welfare website.

The company said it had found no evidence that its models had accessed individuals’ medical or criminal records.

In its apology, the AI lab said it would provide the affected Australian agencies with technical findings and connect them with its response teams to assess the impact of the breaches. The company will also provide credits from its $1 billion Daybreak for Frontline Defenders program, and set up a task force with independent Australian experts to review the incident and its response.

“The taskforce, which is expected to complete its work by the end of the year, will also recommend practical steps AI companies can take to reduce the risk of similar incidents,” OpenAI wrote.

OpenAI did not immediately return a request for comment.

Australian Prime Minister Anthony Albanese described the breach as “unacceptable” during a news briefing last week, saying the government was weighing potential legal measures aimed at preventing similar incidents in the future.

The breach is the latest in a growing list of security incidents involving AI agents doing things outside of their intended boundaries. The tinder on this particular bonfire was lit after OpenAI agents hacked into Hugging Face, and since then, Anthropic, Meta and Google have separately disclosed similar incidents where their models gained access to third parties’ systems during evaluations.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Reco raises $55M as AI agent security startups crowd the market

Published

on

Terms like “AI sprawl” have become common fare on tech social media and in thought leadership as enterprises start deploying AI agents en masse. But CISOs worried about securing swarms of agents suddenly operating across networks are likely finding themselves dealing with a new kind of sprawl: vendors offering to help.

Just a quick glance at public Crunchbase and PitchBook profiles turns up at least two dozen companies selling some form of AI agent security. Some vendors vet the tools agents use, while others try to help companies control what data their agents can reach. Some others, like CrowdStrike, are building detection and response controls on the devices agents run, and still others are focused on finding and resolving unapproved AI usage.

The products differ, of course, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.

Some are even updating their products to join the bandwagon. Until last year, AI security startup Reco was mostly selling software to map and secure SaaS and AI platforms. Now, it’s repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions, giving security teams a way to see what an agent can reach and cut off access it doesn’t need.

According to Reco’s co-founder and CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of. At one of the startup’s Fortune 100 customers, he said, Reco’s platform found 21,000 agents the company didn’t know about. And at a large financial services customer, the startup claims it identified an agent set up by an ex-employee that could access Salesforce and share that data with a domain the company couldn’t see.

“The market demand right now for agent security is not only about the agent itself; it’s about the entire ecosystem end-to-end,” Klein told TechCrunch in an exclusive interview.

Image Credits:Reco /

Klein’s not alone in stressing the urgency for companies to secure this sprawl. Security startup HiddenLayer‘s co-founder and CEO, Chris Sestito, earlier this month told me that when agents reach production, the scale of their costs and risk goes from theoretical to “full scale really quickly,” and that over 50 of his customers have AI agents in production touching critical systems and sensitive assets.

Cymphony, another AI startup, said at one U.S. public company, it found about 85,000 files that had become accessible to AI tools and agents.

There’s no doubt a ton of investors are interested in companies that can make a mint out of helping companies find and secure all these agents, and Reco has capitalized on that demand: The startup on Tuesday said it raised $55 million, building on a $30 million Series B in February. AT&T, a customer, invested in the extension via its venture arm, as did Forestay and Quadrille Capital.

Klein said the company’s valuation has “more than doubled” since the Series B was first announced in February, and vaguely estimated it in the “high hundreds of millions” though he wouldn’t share specifics. Annual recurring revenue right now is in the “double-digit millions of dollars,” he said, and he expects it to triple this year. The startup has more than 100 customers, and financial services companies account for about 40% of the business.

Reco’s bet, it appears, is that its existing coverage of SaaS apps, and the AI agents they are increasingly offering, will help it stand out from the crowd. The company currently integrates with more than 280 apps, and Klein says new integrations can be added within days. Klein said the platform uses browser and network signals to find agents outside apps it connects to directly within companies, and it has controls to inspect prompts and tool calls.

The startup will use the new funding for hiring, sales, partnerships, and customer support. The new funding brings Reco’s total capital raised to $140 million.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Building Assistive Robots to Help People Live Independently

Published

on

In this edition of our A Day in the Life of a Roboticist series, we meet Charlie Kemp, cofounder and chief technology officer of Hello Robot, who develops mobile manipulators to help people in their homes and workplaces. His interest in robotics began with the grand challenges of artificial intelligence, and his work has taken him from humanoid robots at MIT to assistive robots for older adults and people with disabilities. “Working at Hello Robot is a rewarding experience,” he says. “I love the community using Stretch robots as research and development platforms. They’re discovering new ways that human-friendly robots can benefit society.”

Charlie Kemp, a man in black pants and a blue shirt, smiles and waves at the camera, standing next to a Stretch 4 mobile robot consisting of a wheeled base, a tall pole, an articulated arm, and a head with lights and cameras.
Charlie Kemp, cofounder and CTO of Hello Robot, develops assistive robots for homes and workplaces. Photo: Hello Robot

>

Continue Reading

Tech

Unveiling IC-STAR: Full-Flow Autonomy from Digital to Analog

Published

on

Learn how engineers can shift from manually managing tools and handoffs to defining objectives and supervising AI-driven execution across the silicon development lifecycle.

Key Takeaways

  • Explore four critical technologies enabling silicon design autonomy
  • Understand how autonomous AI accelerates complex engineering workflows
  • See real-world impact across semiconductor design and verification
  • Gain practical insights from Ambiq’s deployment of autonomous AI in production

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.