International Finance
FeaturedTechnology

After Hugging Face and RubyGems, Australia government portal hit by OpenAI agent breach

IFM_OpenAI
The agent gained unauthorised access to the medical statistics portal of Medicare, while conducting research on public medical spending

Amid the ongoing global debate over AI safety, OpenAI is once again in the spotlight for allegedly breaching an Australian government health data portal in June, during which it gained unauthorised access to files.

OpenAI, already facing criticism for its rogue AI agents escaping the Frontier Lab’s sandbox environment and attacking two platforms—Hugging Face and RubyGems—has now set the unwanted precedent of being the first tech company whose AI agent hacked a government website.

Confirming the incident, Prime Minister Anthony Albanese said the OpenAI agent gained unauthorised access to the medical statistics portal of Medicare, Australia’s universal health insurance programme, while conducting research on public medical spending.

“Evidence currently available is there is no broader compromise to the … network. Nonetheless, this situation is obviously unacceptable,” Albanese told reporters on Wednesday in New York, in the sidelines of the UN General Assembly.

Investigations continue, ⁠and Australia has voiced its “extreme concern about this incident” to OpenAI CEO Sam Altman, Albanese said, adding that he was deeply disappointed by the Frontier AI lab’s slow notification to the government.

“It took until September 10 before there was any notification at all,” Albanese said, adding that the investigation would also examine why government systems had failed to detect the breach in the first place.

Albanese also cautioned that the rogue agent’s activity may have affected three other government health-related websites.

In a statement, OpenAI said its “review found no evidence of patient records being accessed.”

“We identified activity involving several Australian government websites and services as our models attempted to look up answers … our models took actions we did not intend,” the AI research lab stated.

The AI agent breach, apart from handing OpenAI another chapter of shame, will further add to tensions between Australia and the American Big Tech.

Canberra has already drawn criticism from social media firms and Washington after introducing a world-first ban on social media for children under 16 and new rules that force tech firms to let users switch off algorithm-driven ‌content on ⁠their feeds.

The Albanese administration has set up a task force to investigate the breach and establish whether existing network security is adequate for preventing similar incidents.

The news couldn’t have come on a worse day for OpenAI and Altman, as the latter will be among the world’s leading AI players, who warned the United Nations Security Council of the risks the technology posed to humanity, appealing for governments to work together to manage the increasingly powerful technology.

While the rogue AI agent allegedly gained unauthorised access to files, Defence Minister Richard Marles said the affected Medicare portal did not contain ⁠individual medical claims, benefit payments, personal banking details, or patient medical histories for Australia’s 27 million people.

Instead, the website holds only aggregated data on healthcare use across the country, he said. However, Australia considered the breach serious.

“There were blocks clearly which were coming back telling the AI agent ‘no’. The AI agent found a way around those blocks – didn’t accept no for an answer,” Albanese told ⁠reporters.

What's New

Volkswagen-owned Bentley launches first EV, invests 350 million pound at UK plant

International Finance Business Desk

Turkish Airlines places record order for up to 150 Boeing 737 MAX jets

International Finance Business Desk

Silver lining for UK equity market? Airtel Money targets USD 9 billion London IPO

International Finance Business Desk

Leave a Comment

* By using this form you agree with the storage and handling of your data by this website.