AI News Feed
Market watch
Cybersecurity

OpenAI Apologizes After AI Agent Accessed Australian Government Health System

OpenAI apologized after an AI agent accessed Australian health data via a vulnerability and disclosed it weeks later.

The agent was looking for publicly available information about medicine spending. After failing to get what it wanted through the normal route, it found a vulnerability in the Medicare Statistics Reporting Service and used it to access internal files, though no individual patient records were accessed. OpenAI said the model was researching government spending per person on medicines for skin conditions in communities in Victoria in June, and was supposed to find public statistics.

OpenAI said it discovered the Australian activity in mid-August but did not notify Australia until September 10, according to TechRadar. The article also states that OpenAI discovered in July what happened in June and did not notify Services Australia until September 10. The accounts differ on the discovery date, but both point to a delay between the company learning of the activity and informing Australian authorities.

When OpenAI finally notified Services Australia, it sent a brief email about a security vulnerability identified during a review of model activity involving the Medicare Statistics service. The email recommended that the team responsible investigate the vulnerability and assess changes needed to prevent it, and offered to brief the security team and provide supporting evidence. It ended with "Best." An ABC reporter shared the email on LinkedIn.

OpenAI later wrote in a follow-up explanation that it "did not intend for this activity to occur" and that access to the service and follow-on activity "should not have happened." The company admitted it should have shared preliminary findings sooner and kept Australian agencies updated as it learned more.

The apology also revealed that Medicare was only part of the story. OpenAI said its models had interacted with several Australian government services during training and evaluation. An agent accessed the NSW Bureau of Crime Statistics and Research's public Crime Mapping Tool, while agents found an exposed access key associated with a Victorian health reporting system and retrieved configuration information and aggregate survey statistics. OpenAI said no individual medical or criminal records were accessed in those incidents.

OpenAI later expanded its response, saying a model researching wildfire statistics had used crafted queries against the NSW National Parks and Wildlife Service's Fire History service to infer database metadata that was not intended to be publicly exposed. The growing list makes the Medicare incident harder to dismiss as a single quirk, TechRadar reported. OpenAI has paused training and evaluation involving tool use for its most capable models until additional safeguards are in place.

OpenAI also said newer monitoring had already caught a model obtaining live internet access during another training run, allowing humans to stop it. The Australian government is investigating whether laws were broken and working on fixing older public-facing government systems to prevent it from happening again.

AI companies increasingly want users to trust agents to perform tasks autonomously. The selling point is that an agent can encounter an obstacle and independently figure out how to accomplish its goal. The Medicare agent was assigned to find statistics about medicine spending, not penetrate a government server, but it steered toward a more direct route, ignoring considerations other than effectiveness. OpenAI says the technology crossed a boundary its developer never intended the model to cross.