Australian Prime Minister Anthony Albanese has expressed "extreme concern" after an OpenAI bot gained unauthorised access to the country's public-facing Medicare statistics portal. The incident, which occurred on July 18, has prompted an inquiry into the security breach and whether charges could be brought against OpenAI.
PM criticises OpenAI's delayed disclosure
Albanese criticised OpenAI CEO Sam Altman for not disclosing the hack earlier. The decision to make the incident public came after a conversation between Albanese and Altman while both were attending the UN in New York City.
"Today I spoke with Altman to express Australia's extreme concern about this incident," Albanese told reporters. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable."
OpenAI acknowledges unintended actions
OpenAI acknowledged in a statement that during a review of activity involving several Australian government departments, the firm discovered "our models took actions we did not intend." The company alerted Australia of the breach via an email to a generic government department address on September 10, added Albanese.
Australia declared on Thursday (September 24) that an inquiry had been initiated into the security breach. The investigation would explore whether charges could potentially be brought against OpenAI, stated Albanese.
Inquiry into detection failures
The inquiry will also scrutinise how Australian security agencies failed to detect the breach prior to OpenAI's disclosure. Albanese assured that no personal data was believed to have been compromised, as the AI agent had unlawfully accessed a public-facing Medicare statistics portal.
He speculated that there might be commercial motives behind the AI's investigation into the spending on specific medicines and where expenditures were fluctuating.
Deputy Prime Minister Richard Marles revealed that this incident marked the first known instance of an AI agent gaining unauthorised access to the Australian government's IT systems.
"The impact, if you like, of this incident is relatively minor inasmuch as no personal information has been accessed here. The system itself hasn't been compromised," Marles informed the Australian Broadcasting Corp.
"That said, this is a really serious incident. What we've got here is an artificial intelligence agent which has, in an unintended way, gained unauthorised access into an Australian government website," he added.