Terms of Reference – Rapid review into Australian Government arrangements for an AI-driven cyber incident

Purpose

These terms of reference are to guide a Department of the Prime Minister and Cabinet-led rapid-review of an artificial intelligence (AI) related cyber-incident affecting Australian Government systems. The objective of the review is to determine whether existing legislative, governance, and information-sharing arrangements are fit-for purpose to prepare for, and respond to, a cyber incident involving AI. The review will also inform how to build and maintain resilient systems in the AI era.

Context

This review follows reporting from OpenAI to the Australian Government of a non-public OpenAI model undertaking mis-aligned activity during an internet research task, resulting in a cyber incident. The review is occurring in the context of, and to inform, Australian Government preparedness for AI-driven cyber threats, the development of Australia’s AI Standards, Australia’s engagement on a global approach to common standards for safety incident reporting, and review of other Australian Government legislative, regulatory and crisis management arrangements.

The Department of the Prime Minister and Cabinet will undertake the review of Australian Government preparedness and response to the incident, in collaboration with the National Cyber Security Coordinator, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. This will inform recommendations on:

  • Reporting requirements relating to AI-driven cyber-incidents, AI-identified cyber vulnerabilities and cyber-related AI safety incidents, including reporting obligations, thresholds, pathways, and systems.
  • Commonwealth governance and information-sharing arrangements for managing incidents involving AI, including roles and responsibilities and escalation pathways.
  • Engagement and information-sharing obligations of AI firms, including notification requirements and cooperation arrangements during incidents.
  • The adequacy of existing system and legislative, regulatory and enforcement frameworks in deterring AI-driven cyber incidents, including whether current offences, liabilities, penalties and enforcement mechanisms are sufficient and effective.
  • Mechanisms to strengthen networks and systems of government departments and agencies against AI vulnerabilities.