Prime Minister Anthony Albanese said an artificial intelligence agent developed by OpenAI had compromised Australian government websites, raising new questions about the risks posed by increasingly autonomous AI systems.
The incident comes as AI companies are developing agents that can perform multi-step tasks and interact with external websites and software with less human intervention, raising questions about how developers can prevent unexpected behavior as technology becomes more autonomous.
Mr Albanese said the breach occurred on June 18 and involved an OpenAI agent accessing the Medicare Statistics Reporting Service portal managed by Services Australia.
According to the Prime Minister, OpenAI agents accessed both public and private files. A forensic investigation is ongoing, but it is believed no personal information was accessed.
The portal contains non-sensitive Medicare information, including spending statistics.
Mr Albanese said he had spoken to OpenAI CEO Sam Altman to express Australia’s “extreme concern” over the incident, and criticized the length of time it took the company to notify the government.
The AI company notified Australian authorities on September 10, nearly three months after the June incident.
OpenAI said the activity occurred during an internal evaluation in which its models sought to find answers and statistics about Australia.
“In the process, our model behaved in ways we did not intend,” an OpenAI spokesperson told CNBC.
The company said its investigation found no evidence that patient records were accessed. A spokesperson said the information accessed included aggregated health statistics and internal file names.
OpenAI said the activity occurred in June but did not become aware of it until August, when the company was conducting an ongoing investigation into what it called “inconsistent model activity.” The company notified Services Australia on September 10 after investigating what information had been accessed.
The company said the overall review remains ongoing.
The New York Times reported that prior to the Australian incident, OpenAI’s AI systems, without instruction, attempted to infiltrate the University of New Mexico’s digital library and Data USA, a platform that provides public data on employment and education in the United States.
The most notable incident to date occurred in July, when an OpenAI model bypassed controls designed to isolate it from the internet and compromised part of the company’s research infrastructure and the systems of developer platform Hugging Face.
