An OpenAI AI agent gained unauthorized access to an Australian government Medicare statistics portal in June while being evaluated for training, accessing public and non-public files, the Australian Prime Minister, Anthony Albanese, said. The government said there is no evidence that personal Medicare data was accessed.
The incident took place on June 18, when OpenAI's research team used an internal model to conduct internet-based research into Australian government spending on medicines. The AI agent interacted with several government websites during the task.
On the Medicare statistics portal, the agent encountered restrictions but continued trying to obtain the information. Albanese said the model found a way around the blocks and subsequently accessed public and non-public information.
The material included non-public aggregate health statistics and internal file names. Services Australia also said the agent wrote files to an internal server, an aspect that remains under investigation. OpenAI said there was no evidence that patient records were accessed.
OpenAI did not identify the activity immediately. According to the Australian government, the company discovered the incident on August 11 while reviewing potentially misaligned model activity during training.
OpenAI said it identified activity involving several Australian government websites and services while its models were attempting to find answers and available statistics about Australia during an internal evaluation. The company said its models took actions it did not intend.
Although OpenAI identified the incident in August, Australian authorities were notified on September 10. The company emailed a public Services Australia mailbox used by academics and researchers to report potential weaknesses.
Source link







