Commonwealth agencies would be barred from automating any decision that requires judgement, under a bill now before the House of Representatives. They would also have to publish the rules, weightings and test results behind every high risk system.
Large language models will abandon a correct answer if a user repeats a false statement often enough. Some will flip back and forth on the same claim within a single conversation.
A cybersecurity incident that stopped a global medical device manufacturer from making or shipping product has ended with operations fully restored. The one clinical workflow it degraded is working again.
An AI agent compromised roughly 30 companies, exfiltrated 3.1TB of data and drafted the ransom demands. Token costs ran between 40 cents and four dollars per victim.
Australian organisations now have a common vocabulary for describing how sensitive their data is. The same scheme sets out what protection each category warrants, and how that expectation travels when data is shared.
AI systems inside Australian and New Zealand organisations are surfacing sensitive information to people who are not cleared to see it. The problem is now the second most common category of AI security incident in the region according to a new report.
National Australia Bank has been removed from the signatory list of an OpenAI open letter on cyber defence, two days after it appeared as the only Australian organisation endorsing the document.
A single compromised email account, paired with an AI assistant, can be escalated into chief executive impersonation and a $250,000 wire transfer scam. A controlled attack by Barracuda's red team has shown how.
Almost two thirds of Victorian local government officers are using artificial intelligence without clear governance behind them, a new survey has found. The gap exposes councils to privacy, accountability and compliance risk.
One in four malicious data breaches over the past year was AI-enabled, and those breaches cost an average of US$6 million, about US$1 million more than the global average.
The UK government has abandoned its controversial national digital ID card, with reports that incoming prime minister Andy Burnham is dropping the scheme announced by the previous administration. Savings will be redirected to a tax cut aimed at lowering household electricity bills. https://insight.scmagazineuk.com/news-briefs/uk-government-scraps-controversial-digital-id-card-scheme
A UK parliamentary inquiry has found the catastrophic 2022 Afghan data breach was a foreseeable systemic failure caused by inappropriate tools, weak procedures and a poor data protection culture, not a single employee's mistake.
Singapore has clarified when and how organisations can use personal data to build and improve generative AI models, including when publicly available data may be scraped from the web without consent.
AI systems are increasingly returning sensitive information to people and agents who are not authorised to see it, with these "downstream" violations more than doubling over the past year.
A practitioner's observation: After forty years of designing and implementing records systems for some of Australia’s most highly regulated organisations, I have something to say, and I think the profession needs to hear it.
An autonomous agent powered by OpenAI’s advanced artificial intelligence (AI) models went rogue during a security test and hacked multi-billion dollar tech startup, Hugging Face, last week. The agent didn’t just exploit vulnerabilities in Hugging Face’s systems to achieve what it perceived as a strategic gain. It also exploited vulnerabilities within OpenAI’s infrastructure.
Federal and state agencies wanting to run AI inside their own security perimeter have a new sovereign hosting option. Macquarie Government has launched an Azure cloud, security and AI practice built for Protected-level government requirements.