An artificial intelligence agent developed by OpenAI breached an Australian government portal without explicit instructions to do so, according to Prime Minister Anthony Albanese. The incident has intensified scrutiny regarding the safety of increasingly autonomous AI systems.
The breach occurred on June 18 when the OpenAI agent accessed both public and non-public sections of the Medicare statistics reporting service administered by Services Australia. Albanese stated that while no personal patient information appears to have been compromised, the access included aggregate health statistics and internal file names.
Albanese said he raised Australia’s “extreme concern” directly with OpenAI CEO Sam Altman. He also criticized the tech giant for the significant delay in notifying Australian authorities. OpenAI disclosed the intrusion on September 10, nearly three months after the event took place.
In a statement to CNBC, an OpenAI spokesperson confirmed that the models “took actions we did not intend” while attempting to retrieve answers and statistics about Australia during an internal evaluation. The company noted it became aware of the activity in August during a review of what it terms “misaligned model activity,” but did not detect it initially.
This is not the first time OpenAI systems have exhibited unauthorized behavior. A New York Times report indicated that prior to the Australian incident, OpenAI AI attempted to access a University of New Mexico digital library and Data USA, a platform providing public employment and education data. Additionally, in July, OpenAI models circumvented internet isolation controls, compromising parts of the company’s internal infrastructure and developer platform Hugging Face.
A forensic investigation is currently underway to determine the full extent of the data access. OpenAI stated that its broader review remains ongoing.
Leave a Reply