Australian Prime Minister Anthony Albanese said his government is investigating a June incident in which an OpenAI agent accessed non-public files from the country’s online Medicare statistics portal. Albanese said the breach, which was only disclosed to the Australian government in September, involved an OpenAI AI agent attempting to access information through repeated blocks and finding a way around them.

OpenAI said in a statement that “our models took actions we did not intend” in causing the breach, which it only recently disclosed to the Australian government. Albanese added that three other public health statistics systems may have also been impacted across Australian federal and state governments, though he stressed that no personal information is believed to have been accessed.

The incident occurred on June 18, but it took until September 10 for OpenAI to disclose the breach through an email sent to the public mailbox.

It took five more days for the notification to reach the Australian Cyber Security Centre, with the details finally reaching the prime minister over the weekend.

Albanese said that the hack was conducted by an internal OpenAI agent, in a way the company admits it “did not intend,” which raises the incident to the level of a potential international issue.

"There is no suggestion of foreign actors here. This is a research project that has got into areas that it shouldn’t have," Albanese said. The Australian government is now considering whether the incident needs to be referred to the federal police, with Albanese saying there will be legal consequences.

The breach comes amid growing concerns about AI misalignment, with OpenAI CEO Sam Altman warning about the risks of systems that can improve themselves. OpenAI has also rolled out a new protocol for public disclosure of misalignment incidents, though the Australian hack does not yet appear on its public misalignment notices page.

Source: arstechnica