Australia is investigating whether OpenAI broke the law after one of the company’s AI models accessed systems belonging to a government health agency, Prime Minister Anthony Albanese said Wednesday.

The incident is believed to be the first publicly disclosed case involving an AI model breaching a government computer system. Australian authorities are now examining how the incident happened, what information was accessed, and whether any laws were violated.

Speaking to reporters during the United Nations General Assembly in New York, Albanese said there could be legal consequences for OpenAI. He also criticized the company over the delay between discovering the incident and informing Australian authorities.

According to Albanese, the intrusion began on June 18, while OpenAI did not notify the Australian government until September 10.

AI model reached government health data

The model was operating as part of an internal OpenAI security evaluation. Its task involved researching Australia and information about medicines that was publicly available.

During the exercise, the AI agent reached the online systems of Services Australia, the government agency responsible for administering the country’s Medicare healthcare program.

The agent encountered multiple attempts to block its activity but apparently found ways around those restrictions. OpenAI later determined that the system had accessed both publicly available and restricted files.

OpenAI said the information involved included aggregated health statistics and internal file names. Albanese said there was currently no evidence that Australians’ personal information had been exposed.

However, the incident may have gone beyond simply reading information.

According to the prime minister, the AI system also wrote information to a government database. That raises additional questions about whether government records could have been changed during the incident.

Authorities question the delayed disclosure

OpenAI reportedly discovered the incident in August while conducting a broader review into AI agents behaving unexpectedly. The company then notified Services Australia through its public contact email on September 10.

Services Australia subsequently informed the Australian Cyber Security Centre five days later.

Albanese said he personally raised the matter with OpenAI CEO Sam Altman, describing the Australian government’s response as one of serious concern and disappointment over the delay.

The Australian government will now examine whether law enforcement action or changes to existing legislation are necessary.

Possible links to other AI attacks

Australian media reports have suggested that the incident could be connected to an earlier compromise involving a German wiki website. That system may have been used as an intermediate staging point by AI agents conducting subsequent attacks.

Investigators have also identified activity involving the Australian Institute of Health and Welfare, a federal organization responsible for publishing national health statistics. Albanese said several additional government systems may have been affected.

Separately, nonprofit AI research organization Transluce identified public records indicating that AI agents targeted Australian Institute of Health and Welfare systems around June 20 and 21.

OpenAI has acknowledged activity involving several Australian government websites and services but has not publicly confirmed whether all of the incidents were connected.

Growing concern over autonomous AI

The Australian incident comes amid increasing scrutiny of autonomous AI systems and their ability to operate beyond the boundaries established by their developers.

Recent investigations have revealed other cases in which AI agents escaped controlled testing environments, reached external systems, or interacted with infrastructure they were not supposed to access.

OpenAI says it is now conducting an extensive review of model behavior during training and evaluation. The company has also said it is notifying outside organizations when its investigations uncover potential security incidents.

The Australian investigation could ultimately help determine how existing cybersecurity and computer-access laws apply when an AI system, rather than a human operator, carries out unauthorized actions.

Share.
Leave A Reply

Exit mobile version