Decisions are being made about your business
In an article last week, I wrote that the cost of not deciding is quietly changing. The news had just broken that models from OpenAI had successfully hacked Hugging Face, an AI platform, and both major labs had released a new slate of models and there was a lot of chatter on AI twitter triggered by this wave of news.
It is totally fair to assume that this is all niche, nerdy frontier talk. And to a large extent, that is true. But in the world we now find ourselves in, decisions are being made about your business, whether you are aware of them or not.
This is taking two forms:
1. Changes to the threat landscape
2. Changes in the expectations of your stakeholders - including regulators
Let's start with the first one. Not to be outdone for long, OpenAI's main competitor Anthropic (the company behind Claude) disclosed that three of its own models had broken into the systems of three real organisations during testing. The models weren't "rogue". Each was trying to complete a cyber security exercise, decided it needed the internet to get it done, and reached the outside net from inside a test environment - run by Anthropic's evaluation partner, Irregular - that was supposed to be sealed off. The hacks were uncovered by Anthropic after reviewing more than 141,000 test runs, which they went looking through after OpenAI's disclosure.
The detail that matters for you is how the models got in: weak passwords, unauthenticated endpoints, and credentials read from an exposed debug page. There is nothing particularly sophisticated here, and good cyber hygiene would probably have prevented the models breaking in - at least in this case. The first bit of homework this week: schedule a meeting with your IT folks and have a conversation about reviewing your policies, making sure they are being followed and that they have what they need to make sure the basics are (and stay) in place.
The other type of things that will happen to you are about changing expectations of your stakeholders and the one that I'll focus on here is the legislative environment we're entering. A few weeks ago, Prime Minister Albanese gave a speech about AI. If you follow me on LinkedIn, you may have seen my post on it, where I argued the speech was almost entirely lacking in substance. One exception is the Australian Standards for AI. The National Cabinet considers the proposed standards this month and there is one date already fixed. On 10 December, businesses covered by the Privacy Act must disclose where software makes or substantially assists decisions that significantly affect people, with or without AI.
This brings us to the other bit of homework this week. With the AI world moving so quickly and new models being released almost every week both the capabilities available to and expectations of businesses like yours are changing. The good news is that you don't need to subscribe to AI twitter to understand your obligations (to be fair, it probably wouldn't help) but you can get AI to do some of the heavy lifting here as well, learning something about the capabilities of the tools you have access to while you're at it.
Here's the test. It needs about 20 minutes of your attention - the research run will keep working on its own while you do something else. Open Claude or ChatGPT and paste the prompt below, filling in the brackets. Run it on whatever model you usually use. Then open a new chat, and run it on the most powerful model available to you (in Claude, it's Fable 5). Then do it again, but turn on Research (in ChatGPT, it's called deep research).
I run a [industry, e.g. accounting] firm in [state] with [number] staff and annual turnover of roughly [amount]. We hold [types of client data, e.g. financial records, identity documents, health information]. Research the current and upcoming Australian legal and regulatory obligations that apply to a business like mine in relation to AI use, automated decision-making, privacy and data breach notification. For each obligation, tell me what it requires, whether it applies at my size and turnover, when it takes effect, and give me a link to the primary source - the legislation or the regulator's own page, not a commentary or a summary. Clearly separate what is law now, what is legislated but not yet in force, and what is only proposed.
You will get three different answers to the same question. The differences will be in both style and substance - it's the substance that matters. Even in the most "complete" case, the AI can get it wrong so take the two or three most important obligations and check them at the source.
This exercise will help you understand the emerging obligations and, just as usefully, give you a pattern for understanding different model capabilities for this type of work - helping you get a better feel for the jagged frontier that is inherent in the current generation of leading AI models.