An AI agent developed by OpenAI gained unauthorized access to an Australian government Medicare statistics portal in June, reaching public and nonpublic files.
OpenAI said in a statement to Becker’s that the activity occurred as its models attempted to answer questions about Australia during an internal evaluation and that the models “took actions we did not intend.”
The incident occurred June 18, when OpenAI’s research team used an internal model to conduct internet-based research into public medicine spending, Australian Prime Minister Anthony Albanese said at a Sept. 24 press conference in New York.
After encountering repeated blocks while seeking information, the agent attempted alternative ways to obtain the data and gained unauthorized access to other areas of the Medicare Statistics Reporting Portal, which is administered by Services Australia.
Mr. Albanese said the agent accessed public and nonpublic information within the portal, and Services Australia advised that it also wrote files to an internal server.
OpenAI said its review found no evidence that patient records were accessed.
“The information accessed included aggregate health statistics and internal file names,” OpenAI spokesperson said in a statement to Becker’s.
Mr. Albanese described the portal as public-facing and said it contains nonsensitive statistics, including spending data. He said no personal information is believed to have been accessed and there is currently no evidence of a broader compromise of the Services Australia network.
A forensic investigation involving the Australian Signals Directorate is ongoing.
OpenAI said it identified activity involving several Australian government websites and services while reviewing what it described as misaligned model activity during training and evaluation.
The company said it is notifying third parties when its review identifies potential impacts to their systems and is providing the organizations with technical information to support their investigations and help address potential security vulnerabilities.
The Australian government is investigating whether three other systems may have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.
Mr. Albanese said the potential activity involving those systems was part of the same incident but stressed that the government has not confirmed they were accessed.
At a separate Sept. 24 press conference in Sydney, Acting Prime Minister Richard Marles said the model interacted with four public Australian websites. He said its interactions with the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research were normal and involved public information, and that only the Medicare portal was accessed without authorization.
OpenAI did not notify the Australian government about the June 18 incident until Sept. 10, Mr. Albanese said. The notification was sent by email to a public Services Australia mailbox.
Services Australia reported the notification to the Australian Cyber Security Centre on Sept. 15.
OpenAI said it did not become aware of the June activity until August, during its ongoing review of misaligned model activity, and that it spent the time before the Sept. 10 notification validating and investigating the facts and what information had been accessed.
The company said its initial notification followed common industry practice: direct outreach between security practitioners through designated inboxes as the first step in an ongoing technical engagement. ABC News reported that the address OpenAI emailed is used by academics and researchers to report weaknesses in Services Australia’s systems.
OpenAI also said it maintained close, regular contact with the Australian Signals Directorate throughout the technical disclosure process and shared technical findings and relevant information following its guidance.
Mr. Albanese said he spoke by phone with OpenAI CEO Sam Altman on Sept. 24 and expressed concerns about both the incident and the company’s notification process.
Mr. Albanese said Mr. Altman acknowledged issues with OpenAI’s protocols.
“This is a research project that has got into areas that it shouldn’t have,” Mr. Albanese said.
The Australian government is establishing a task force, led by Mr. Albanese’s department, to review the incident and assess whether existing processes are adequate to respond to AI-related cyber incidents.
The task force will involve the National Cybersecurity Coordinator, Office of AI, Australian Signals Directorate, Australian AI Safety Institute and Services Australia.
The government will also refer the incident to Parliament’s Joint Select Committee on Artificial Intelligence and seek advice on whether any offenses occurred and whether the incident should be referred to the Australian Federal Police. Mr. Albanese said insights from the incident will inform the development of Australia’s AI standards legislation.
OpenAI said its broader review remains ongoing and that it plans to continue sharing information as the work progresses.