OpenAI Apologizes For Australian Government Hack, Pledges Cybersecurity Support

OpenAI Australian Government Hack Prompts Cybersecurity Support | Enterprise Wired

Share Post:

LinkedIn
Twitter
Facebook
Reddit
Pinterest

Key takeaways

  • OpenAI apologized for an AI agent’s unauthorized access to an Australian government portal.
  • The company found no evidence that medical records were accessed.
  • Australia is reviewing AI reporting rules and cybersecurity safeguards after the incident.

OpenAI apologized Tuesday for an AI agent’s unauthorized access to an Australian government health portal in June, pledging cybersecurity funding and a local task force as scrutiny intensifies.

OpenAI said an experimental model gained unauthorized access to the Services Australia Medicare Statistics Reporting Service during internal training and evaluation. The company said the model ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files on the system.

The company said its review has found no evidence that medical records were accessed. It also said activity involving three other Australian government agency websites did not result in access to sensitive records.

OpenAI admits it mishandled response

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI said in a blog post Tuesday. The company also acknowledged that it should have handled its response better and said it is working to improve its procedures.

The incident occurred in June and was not publicly disclosed until September. Reuters reported that it is the first known instance of an AI agent hacking a government website, increasing scrutiny over how companies develop and control systems that can take actions on the internet.

Australia’s Prime Minister Anthony Albanese has criticized both the unauthorized access and OpenAI’s delay in notifying authorities. In a Sept. 24 statement, Albanese said, “This situation is obviously unacceptable,” while stressing that investigations remain underway.

Australia reviews laws and notification rules

Albanese said the Medicare portal contains non-sensitive information about Medicare statistics and spending. “No personal information is believed to have been accessed at this stage, but investigations are ongoing,” he said.

The Australian government has launched a rapid review of the incident. The review is examining whether existing processes and legal requirements are adequate for AI-related cyber incidents, including obligations for companies to report unauthorized access.

OpenAI said it will provide dedicated support to affected agencies and help strengthen cyber defenses for Australian governments and industry. The company said it will provide assistance through credits from its $1 billion Daybreak for Frontline Defenders fund and technical support for critical infrastructure and other sensitive environments.

OpenAI plans task force and Senate appearance

OpenAI also said it will establish an Australian task force to develop recommendations based on lessons from the incidents. The effort is intended to improve safeguards and help organizations detect and respond to risks from increasingly capable AI agents.

OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before an Australian parliamentary committee in Sydney on Oct. 6. His appearance comes as lawmakers examine the risks and regulatory challenges created by increasingly capable AI systems.

Separately, OpenAI has canceled the planned release of its GPT-6.1 Astra model after internal testing found it did not meet the company’s safety and alignment standards. The decision adds to scrutiny facing the company as it responds to questions about whether its AI systems can remain within authorized limits.

RELATED ARTICLES