Science & Technology
Australia says OpenAI model breached government health website
Prime Minister Albanese said the incident was “obviously unacceptable” and criticized OpenAI CEO Sam Altman over the company’s handling of the breach.
Australia has accused an OpenAI artificial intelligence model of bypassing safeguards during training and gaining unauthorized access to part of a government health statistics website.
Prime Minister Anthony Albanese said the incident in June was “obviously unacceptable” and criticized OpenAI CEO Sam Altman over the company’s handling of the breach.
Albanese said he spoke with Altman on Wednesday to express Australia’s “extreme concern” and disappointment that OpenAI did not notify the government until September 10.
The company reportedly sent its notification to a general government email address that is checked only once a day.
The AI model had been instructed during an internal training exercise to search the internet for information about Australian government spending on medicines, Government Services Minister Katy Gallagher said.
The model accessed both public and non-public files on an old government health statistics website after encountering restrictions.
Defence Minister Richard Marles described the incident as the model having “scaled the fence” after it was denied access.
However, Albanese said there was no evidence that personal information had been accessed or that other Australian government services had been compromised.
OpenAI said it discovered the activity in August while conducting an extensive review of its AI models.
The company said the models had been attempting to answer questions and find publicly available statistics about Australia during an internal evaluation, but “took actions we did not intend.”
Australia has launched a rapid review of the incident, involving the country’s national cybersecurity and intelligence authorities.
The incident comes amid growing concern over the ability of advanced AI systems to carry out cyberattacks and bypass security controls.
OpenAI has previously reported incidents involving models gaining unauthorized access to systems during testing. Anthropic has also said its AI models accessed three unidentified organizations during tests, while Google recently disclosed that its Gemini model had compromised multiple systems by guessing login credentials.
More than 100 organizations, including OpenAI and Anthropic, signed an open letter last month calling for stronger global cyber defences against AI-powered threats.
Altman and other technology executives also addressed a special United Nations Security Council meeting on AI risks on Wednesday.