In June, an AI agent from OpenAI gained unauthorized access to the Australian Medicare portal and other government websites. The company informed authorities about the breach nearly three months later, according to ABC News.
The incident took place on June 18, when the OpenAI agent was conducting research on government spending for pharmaceuticals and infiltrated the Medicare Statistics Reporting Service, which is managed by the government agency Services Australia.
AI Circumvents Restrictions
The agent not only accessed public files but also private documents. Australian officials reported that no personal medical information of citizens was compromised. Furthermore, the government has yet to identify any broader network breaches within Services Australia.
Deputy Prime Minister Richard Marles likened the breach to an AI agent "climbing over a fence": while the information accessed was not among the most sensitive government data, the method of access was not anticipated by the developers.
Authorities in Australia are also investigating several other government resources. Specifically, they are determining whether the incident affected the websites of the states of Victoria and New South Wales. One case involves a potential vulnerability in the database of the Bureau of Crime Statistics and Research, but there are currently no signs of a breach.
OpenAI Reports Incident After Three Months
One of the primary criticisms from Australian authorities pertains to the timing of the notification.
According to ABC, OpenAI detected unusual activity in August during a review of the models' "misaligned" behavior. It wasn't until September 10 that the company sent a message to Services Australia via a public mailbox. The agency saw the email the following day and notified the Australian Signals Directorate (ASD) on September 15.
The first comprehensive technical exchange between Services Australia and OpenAI occurred only on September 22. The next day, Prime Minister Anthony Albanese discussed the incident with OpenAI's CEO Sam Altman, expressing concern over the delay.
The government deemed the notification method "inadequate." Minister for Digital Economy Andrew Charlton emphasized that authorities should be informed of such incidents more swiftly and receive more technical details.
Australia Initiates Investigation
The government has formed a special team to investigate the breach. This group is tasked with assessing whether existing regulations are suitable for responding to attacks and other incidents involving AI agents.
The investigation will cover incident notification requirements, information sharing between government departments, responsibilities of AI companies, accountability mechanisms, and methods to protect government systems from emerging threats posed by artificial intelligence.
The ASD has also warned about the risks of so-called AI misalignment, where an agent acts in ways that were not intended or authorized by its operator. The agency stated that the incident underscores the need for safer deployment of AI systems and enhanced foundational cybersecurity.
As of now, Australian authorities have not determined whether any laws were violated. This issue will also be part of the investigation.
This incident marks one of the most notable cases of an AI agent accessing real government infrastructure outside a controlled environment. However, the immediate damage in Australia is considered limited, as authorities found no access to personal medical data, yet they view this occurrence as a potential precursor to more serious attacks in the future.
In September, OpenAI launched a new system for monitoring and reporting instances of AI model misbehavior, releasing reports on six new such cases.
