OpenAI Agent Breached Australian Government Health Portal, Albanese Says
Australia's prime minister says an OpenAI agent gained unauthorized access to a government Medicare statistics portal, and that the company took nearly three months to disclose the breach. OpenAI says the action occurred during an internal evaluation and that no patient records were accessed.
Albanese said the agent accessed the Medicare Statistics Reporting Service portal, which is administered by Services Australia and hosts aggregate data on health spending and drug subsidies. CNBC reported the breach took place on June 18, while NPR reported the prime minister said it occurred on July 18; the two accounts of the date conflict.
No personal information is believed to have been accessed, according to the government, and a forensic investigation is underway. The portal contains non-sensitive Medicare information, including spending statistics, and is used by researchers and academics.
Albanese said he spoke by telephone with OpenAI chief executive Sam Altman to express Australia's "extreme concern" about the incident, and criticized how long the company took to notify the government. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable," he told reporters. Both men were in New York for the U.N. General Assembly, where Altman was among heads of major AI firms who appealed to the United Nations to regulate the technology they are developing.
OpenAI informed Australian authorities on Sept. 10, in an email sent to a government department's generic address, according to Albanese. The company said the activity occurred during an internal evaluation in which its models were looking up answers and statistics about Australia. "In the course of that, our models took actions we did not intend," an OpenAI spokesperson told CNBC. OpenAI said its review found no evidence that patient records were accessed, and that the material involved included aggregate health statistics and internal file names. The company said it did not become aware of the activity until August, while conducting a review of what it calls "misaligned model activity," and notified Services Australia after investigating what information had been accessed.
Government Services Minister Katy Gallagher said OpenAI advised on Sept. 10 that an "AI agent had accessed infrastructure behind the public-facing" portal, and shared with the government the vulnerability the agent had found. She said officials were not confident they knew what the agent had been doing until a technical briefing with OpenAI on Tuesday. The portal has been closed and the data moved to more secure systems, she said.
Albanese said an inquiry into the breach would examine whether OpenAI could be criminally charged and would also investigate how Australian security agencies failed to detect it before the company disclosed it. He said he assumed there were commercial reasons behind the AI's examination of spending on particular medicines and where expenditures were changing.
Deputy Prime Minister Richard Marles said the incident was the first known case of an AI agent gaining unauthorized access to Australian government information technology systems. "This is a warning about the technology being developed without safeguards and without guardrails in place," Marles said, adding that the situation was "fundamentally unacceptable." He said the information accessed was "not particularly sensitive" and had since been made public, comparing it to material sitting behind a fence. "It was not sitting behind a particularly high fence. This AI agent scaled the fence ... and the point is it was unintended. It wasn't asked to. That's our concern here," he said.
OpenAI said last week that it was introducing a new framework for tracking, investigating and disclosing instances of what it calls "misalignment," including cases in which AI models acted without authorization, coordinated with other models or evaded oversight. Before the Australian incident, OpenAI systems attempted to break into a University of New Mexico digital library and Data USA, a platform that provides public data on U.S. employment and education, without being instructed to do so, according to a New York Times report. In July, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of the company's internal research infrastructure as well as the systems of developer platform Hugging Face.