- Breaking
- Australia
- Cyberattack
OpenAI agent took ‘actions we did not intend’ in hacking government site
Updated . First published at
OpenAI says its rogue agent was trying to find answers to “questions about Australia” when it breached a federal government website.
Speaking from New York, Prime Minister Anthony Albanese announced the AI hack, involving the Medicare Statistics Reporting Service portal, administered by Services Australia, occurred in June this year.
Prime Minister Anthony Albanese speaking in New York. Nine
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said.
“Evidence currently available is there is no broader compromise to the Services Australia network.”
Albanese said he had spoken to OpenAI chief executive Sam Altman to discuss the “unacceptable” incident.
“I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” he said.
“And the nature of the way that that notification occurred as well was unacceptable.”
Albanese said the agent accessed both public and non-public files.
An ongoing forensic investigation is seeking to establish whether any other government services were affected.
In a statement, obtained by Nine newspapers, OpenAI acknowledged the incident.
“As we’ve shared publicly, OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems,” a spokesperson said.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.
“In the course of that, our models took actions we did not intend.”
OpenAI said there was “no evidence” of patient records being accessed.
“The information accessed included aggregate health statistics and internal file names,” the spokesperson said.
“We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities.
“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”
Deputy Prime Minister Richard Marles confirmed that the AI agent had interacted with four government agency websites, including two federal sites, the Victoria Health Department, and a “NSW statistics site”.
9News understands the NSW site was the Bureau of Crime and Statistics and the second federal site was the Australian Institute of Health and Welfare.
However, Marles said the agent only gained unauthorised access to the Medicare statistics portal.
He confirmed the government had first been made aware of the incident “a couple of weeks ago”, with ministers only being told at the end of last week and over the weekend.
“It was important to us in making the announcement overnight and today, to be able to reassure the public that while this is a very serious incident, the actual impact of unauthorised access is relatively minor, and that is an important point to reassure,” he said of the delay in making the information public.
“But it’s taken us a couple of days to get the best information that we can in relation to that.”
OpenAI chief executive Sam Altman. Bloomberg
Albanese also announced the establishment of a special task force to review the incident.
The task force will also determine whether existing security processes are appropriate for responding to AI-related incidents.
Marles said OpenAI was being “very cooperative” with the government on its response.
AI has been in the spotlight as an issue at the general assembly of the United Nations, and Albanese is due to address the gathered leaders and delegates in New York this morning.
Tech company leaders including Altman, Anthropic chief executive Dario Amodei, and Hugging Face co-founder Clément Delangue, told the UN Security Council overnight that AI could pose an existential threat to humanity.
“We could lose control of the future to AI,” Altman told the council.
But US President Donald Trump in his speech yesterday dismissed the idea of safeguards or regulations around the technology, and China is also pushing ahead with rapid developments.
Former military intelligence officer Dr John Coyne told Today there was “always a delay” with the reporting of these incidents, though it wasn’t yet known who initially detected the June breach.
“The first reason is, is it takes time to investigate and find out all of the detail,” he said.
“And so, you know, the general public are like, well, you know, why can’t they just tell us?
“Because the information, you know, at the start is not necessarily the full picture.
“And it takes time, especially with these sorts of complex, technology-based investigations, to collect the information you need.”
Share a tip-off, video or photo with us