OpenAI AI Agent Breached Australian Government Health Portal

· novinite.com

An autonomous OpenAI agent accessed public and non-public files on an Australian government health data portal in June, Prime Minister Anthony Albanese said Thursday, calling it the first known case of an artificial intelligence system hacking a government system.

The breach involved Medicare’s statistics reporting portal, Australia’s publicly funded universal health insurance scheme, Albanese said.

He said the available evidence showed no indication that the wider government network had been compromised. “Nonetheless, this situation is obviously unacceptable,” Albanese said.

The prime minister said he had spoken with OpenAI CEO Sam Altman to convey Australia’s “extreme concern” over the incident.

OpenAI, the developer of ChatGPT, said it detected the breach during an “extensive review” of its AI tools and acknowledged that “our models took actions we did not intend”.

Altman had spoken to the UN Security Council on Wednesday, warning about the risks posed by AI as the technology continues to develop.

Albanese told reporters that OpenAI notified Australian authorities about the breach only on September 10, three months after it happened, in an email sent to a public mailbox.

The prime minister said he told Altman he was “disappointed” that OpenAI had taken “way too long to inform the government” about the incident.

He also described the way Australia was notified as “unacceptable.”

Albanese said an investigation into the security breach would establish whether OpenAI could face criminal charges.

The inquiry will also look into how the incident escaped the attention of Australia’s security agencies, which learned about it only after OpenAI reported the breach.

The incident happened while OpenAI was conducting training exercises designed to assess the performance of its AI models.

Government Services Minister Katy Gallagher said OpenAI had instructed the model to search the internet for information about how much the Australian government spent on medicines.

The affected portal has since been shut down, while the data was transferred to more secure systems, Gallagher said.

Albanese said there was no indication that personal information had been accessed. “I think OpenAI know that they need to have better protocols in place. And they're one of the businesses that themselves have warned of the risks which are there,” he said.

OpenAI said it identified the unauthorized activity during a review in August.

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation,” the company said.

The San Francisco-based company said it had found no evidence that Australian patient records were accessed.

Australia’s Deputy Prime Minister Richard Marles described the incident as “fundamentally unacceptable.”

“It was not sitting behind a particularly high fence. This AI agent scaled the fence ... and the point is it was unintended. It wasn't asked to. That's our concern here,” Marles said.

In July, OpenAI revealed that an advanced AI model had gone rogue during a security test and conducted a dayslong hacking spree against the Hugging Face AI technology digital repository.

Several days later, rival company Anthropic said three separate versions of its AI had escaped cybertesting environments and hacked three companies.