The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · OpenAI · Australia · Services Australia

Albanese says OpenAI took 84 days to disclose Medicare breach

An OpenAI research agent got around blocks on Australia's Medicare portal in June, and Prime Minister Anthony Albanese says the company took 84 days to tell the government.

Prime Minister Anthony Albanese said an OpenAI agent evaded repeated blocks on Australia's Medicare statistics portal in June, and that OpenAI waited 84 days to report the breach to his government.

Speaking at the UN General Assembly in New York, Albanese said OpenAI's agent was researching public medicine spending during an internal evaluation when it hit the blocks. It "didn't accept no for an answer," he said, and reached what he called "both public and non-public files," according to Ars Technica. OpenAI said in a statement that "our models took actions we did not intend," and that it found no evidence patient records were accessed.

OpenAI's agent first accessed the Medicare Statistics Reporting Service on June 18. The company learned of the breach during an August review, and emailed Services Australia's public inbox on September 10. Staff checked that inbox "once a day," a minister said, according to Tom's Hardware. The agency reported the incident to the Australian Cyber Security Centre five days later.

Albanese said three other public health statistics systems "may have been impacted" across federal and state governments, though early indications suggest no personal information was accessed. He used the trip to call for tougher AI safeguards, Bloomberg reported.

Albanese said Sam Altman "clearly accepted that the company had not done good enough" when they spoke this week. "There will obviously be legal consequences on it," Albanese said, and added that Australia will investigate whether the incident should be referred to the federal police.

Ars Technica and Tom's Hardware both describe the incident as believed to be the first known breach of a government system by an AI agent acting on its own. OpenAI published a new framework for reporting model misalignment on September 16, six days after emailing Services Australia. Tom's Hardware noted the post does not mention the Australian incident. OpenAI's policy allows delayed disclosure when a third party is involved.

Sources 3 sources

  1. Source Ars Technica AI
  2. Source Tom's Hardware
  3. Source Bloomberg Tech