‘Our models took actions we did not intend,’ an OpenAI spokesperson said.
OpenAI took weeks to inform Australia that its agents hacked a government website – an admission which comes as the technology giant simultaneously pushes for broader AI safety.
In the latest OpenAI cyber incident to surface, the company’s agents gained unauthorised access into a healthcare statistics portal administered by the Australian government’s welfare agency.
The AI accessed public and non-public files, and rewrote internal files, prime minister Anthony Albanese told the press at the United Nations General Assembly in New York yesterday (23 September). No personal information is understood to have been compromised at this point.
Australia has launched a forensic investigation in response and established a taskforce to review the matter. The government is also establishing whether a crime has occurred, Albanese said.
A matter of ‘extreme concern’
OpenAI’s agents hacked into the statistics reporting portal for Australia’s universal health insurance scheme, Medicare, Albanese told the press.
The incident occurred on 18 June when OpenAI’s research team used an internal model to conduct internet-based research into public medicine spending. The agents were faced with blocks when trying to access data from Medicare, but bypassed them. They “didn’t accept ‘no’ for an answer”, said Albanese.
Three other government systems may have been impacted, he added, including the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Independent research has already shown that advanced AI agents, like those from OpenAI and Anthropic, can take risky and deceptive actions without specific prompting.
“This situation is obviously unacceptable,” the prime minister said. “I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident.”
Altman addressed the United Nations Security Council on Wednesday, touting the benefits of AI while warning of its potential abuses.
An OpenAI spokesperson told news publications that the company only discovered the breaching incident in August after extensive checks into its models’ activity.
The AI giant then took weeks to inform the Australian government of the cyber incident; when notice came, it was in the form of an email sent to the public mailbox on 10 September. This led to a further five-day delay in relevant authorities being informed.
Albanese said that he shared his disappointment with Altman over the delay and the manner in which the company informed his government.
“During [the] review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation,” the OpenAI spokesperson said.
“In the course of that, our models took actions we did not intend.”
The company said it found no patient records to have been accessed in the Medicare breach.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Anthony Albanese, prime minister of Australia. Image: NATO North Atlantic Treaty Organization via Flickr (CC BY-NC-ND 2.0)
You must be logged in to post a comment Login