Explained: How OpenAI breached a government website in Australia and what happens next

Australian PM Anthony Albanese said an OpenAI agent breached a government health website in July, accessing non-public Medicare data. Australia has launched an inquiry into the incident, including OpenAI’s delayed disclosure and how the breach wen...

Agencies
Australian Prime Minister Anthony Albanese said on Wednesday that an OpenAI agent had breached a government website in July, gaining unauthorized access to a public-facing Medicare statistics portal, and making non-public data vulnerable.

Although AI agent-driven breaches of government databases have happened before, this is said to be the first unintentional, non-human-led hacking.

While OpenAI eventually informed the authorities in Australia about the breach, the government was not satisfied with how the ChatGPT maker came clean. "I … expressed my disappointment that it took the company way too long to inform the government of what had occurred, and the nature of the way that notification occurred was also unacceptable," Albanese said during a press conference on the sidelines of the United Nations General Assembly (UNGA) on Wednesday.



How did the breach occur?

On July 18, an OpenAI agent accessed both public and non-public information from an Australian health department website.

ADVERTISEMENT
According to Albanese, an OpenAI research team had initially been using an internal model for internet-based research into public medicine spending.

The AI agent encountered blocks while attempting to obtain information but subsequently found ways around them, leading to unauthorised access to other areas of the portal, the prime minister said.

Albanese added that no personal information was believed to have been hacked.

When did the incident come to light?

ADVERTISEMENT
OpenAI said in a statement that during a review of activity involving several Australian government departments, the company discovered that its models took unauthorised actions.

The ChatGPT maker subsequently notified Australia of the breach, writing to a generic government department email address on September 10.

ADVERTISEMENT
What happens next?

Australia announced on Thursday that an inquiry had been set up to look into the security breach. The probe would examine whether OpenAI could potentially be charged, Albanese said.

The inquiry will also examine why Australian security agencies failed to detect the breach before OpenAI revealed it.

The revelations come in the wake of global discussions around the need for safety from AI agents, which are increasingly moving across systems and taking decisions on their own.

Australia was among 22 countries that signed a joint statement this month calling for global oversight and guardrails for AI development.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › Tech › AI › Explained: How OpenAI breached a government website in Australia and what happens next
Text Size:AAA
Success
This article has been saved

*

+