OpenAI's AI agent breached an Australian government system, and took three months to disclose it

The agent bypassed access restrictions during a research task, with officials now checking for further breaches

by · TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

What we know so far: AI agents going rogue and breaching other companies' systems is bad enough, but Australia says this trend has taken a worrying turn. An OpenAI agent gained unauthorized access to a government Medicare statistics portal in June, prompting an investigation into whether other systems were affected. Making matters worse, authorities weren't notified until September.

Prime Minister Anthony Albanese said the June 18 incident involved a portal administered by Services Australia. The agent was researching public medicine spending during an internal OpenAI evaluation when it encountered access restrictions and circumvented them.

There's some reassuring news: this wasn't a raid on Australians' individual medical histories. OpenAI says its review found no evidence of patient records being accessed, with the information including aggregate health statistics and internal file names, Reuters reports.

OpenAI became aware of the breach on August 11 but didn't notify Services Australia until September 10, nearly three months after the intrusion. Albanese said he expressed Australia's extreme concern to Sam Altman and criticized both the delay and the decision to send the notification to a public mailbox.

OpenAI said the activity emerged during a broader review of misaligned behavior in training. "Our models took actions we did not intend," the company acknowledged. It says it is supplying technical information to affected organizations and that its review remains ongoing.

Australia's response includes a forensic investigation assisted by the Australian Signals Directorate and a taskforce examining the incident, government network security, and arrangements for handling emerging AI threats.

There have been suggestions that four government websites were breached. But acting Prime Minister Richard Marles clarified that interactions with the Australian Institute of Health and Welfare, Victoria's health department, and the NSW Bureau of Crime Statistics and Research involved normal access to public information. The confirmed unauthorized access was limited to the Medicare statistics portal.

// Related Stories

This is just the latest addition to a growing list of concerning AI incidents. It was reported on September 4 that agents had turned a German programming wiki into a message board for swapping answers and techniques for bypassing restrictions. There's also been a Senate investigation into OpenAI's handling of the separate Hugging Face breach, with Josh Hawley demanding answers from Altman by October 1.

The breaches have fueled calls to slow AI development, while Bernie Sanders threatened Senate action unless OpenAI, Anthropic, and Meta paused their work. Elsewhere, Washington and Beijing have discussed a proposed AI incident alert system to warn each other about potentially dangerous activity, although exactly how it would operate remains unclear.

See more TechSpot in Google Add us as a preferred source and our reporting shows up first when you search.
Add TechSpot