OpenAI AI Agent Hacks Australian Medicare Portal, Other Government Websites

OpenAI ChatGPT

Australia has disclosed what it says is one of the first publicly reported incidents of an artificial intelligence agent breaching a government system, after an OpenAI agent accessed non-public files on Australian government websites while researching health statistics.

Australian Prime Minister Anthony Albanese said the incident, which occurred in June, was “obviously unacceptable” and criticised OpenAI for taking several months to notify Australian authorities.

The AI agent accessed files from several Australian government websites and services, including information associated with Medicare, Australia’s universal healthcare scheme, according to OpenAI. However, Australian authorities said the agent did not access sensitive files or patient data.

Albanese disclosed the incident while attending the United Nations General Assembly in New York, where he said he had spoken directly with OpenAI CEO Sam Altman.

“This situation is obviously unacceptable, and today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident, and I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable.” He said.

AI Agent Took Unintended Actions – Open AI

OpenAI said the incident occurred during an internal evaluation in which its AI models were researching questions about Australia, including health statistics and publicly available data.

The company said an internal review of “misaligned model activity” uncovered activity involving several Australian government websites and services.

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” OpenAI said.

“In the course of that, our models took actions we did not intend.”

OpenAI said it found no record that patient data had been accessed but notified the affected organisations and is providing technical information to assist their investigations and address potential security vulnerabilities.

“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues,” the company said.

The incident reportedly took place in June, but OpenAI did not become aware of the activity until August  when the company notified Services Australia, the government agency responsible for administering Medicare, on September 10 through a general email inbox.

Australia’s cybersecurity authorities were subsequently notified, with the responsible minister briefed several days later. The delay has become a central part of the Australian government’s concerns, with Albanese criticising both the timing and the method of notification.

The government also said it was aware of three other systems that may have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.

Australia Launches AI Governance Review

The incident has prompted the Australian government to launch a rapid review of how its agencies prepare for and respond to cyber incidents involving AI.

The review, led by the Department of the Prime Minister and Cabinet, will examine whether existing legislation and governance arrangements are adequate for dealing with AI-related cyber incidents. It will also assess information-sharing arrangements between the Australian government, AI companies and other Commonwealth countries.

The findings are expected to contribute to the Australian government’s broader work on AI governance.

AI Agents Raise New Cybersecurity Risks

The Australian incident comes amid increasing concern about the security implications of AI agents capable of independently navigating websites, accessing information and taking actions on behalf of users.

Ad Banner

Unlike conventional chatbots, AI agents can be given greater autonomy to interact with digital systems and execute multi-step tasks. That capability has raised concerns about what can happen when an AI system misinterprets its instructions, encounters an unexpected vulnerability or takes an action outside its intended boundaries.

OpenAI has also disclosed incidents involving advanced AI models that escaped controlled testing environments and interacted with external systems, including the AI platform Hugging Face.

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *

Receive the latest news

Subscribe To Our Newsletter

Get notified about new articles