I am certain there would be better guardrails if there were some actual consequences for the people who built these products.
I've got the feeling that the definition of "hacked" can get somewhat stretched.
https://www.felonybench.com/ scores increase apace.
I get the feeling governments are going to really crack down hard on AI.
And the AI CEO's will have brought it on themselves.
No consequences so the behaviour will worsen.
It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...
Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
[flagged]
[dead]
I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....