Get all your news in one place.
100's of premium titles.
One app.
Start reading
The National (Scotland)
The National (Scotland)
National
[email protected] | Marco Suttie

AI agent infiltrates government health website prompting urgent review

(Image: PA)

AN OpenAI agent gained unauthorised access to an Australian government health website in what is believed to be one of the world's first known AI-led breaches of a government system.

An urgent review has now been launched into the incident, including whether any laws were broken, as Australian Prime Minister Anthony Albanese said he had personally raised his government's "extreme concern" with OpenAI chief executive Sam Altman.

The AI agent accessed infrastructure behind a public-facing Medicare statistics portal, which contains aggregate information about health spending and drug subsidies and is widely used by researchers and academics.

The Australian government said there was no evidence that personal patient information had been accessed.

However, Albanese criticised OpenAI for taking "way too long" to alert officials to what had happened and described the way the company notified the government as "unacceptable".

"Today I spoke with [Sam] Altman to express Australia's extreme concern about this incident," Albanese told reporters.

"I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable."

OpenAI said it had reviewed activity involving several Australian government departments and discovered that "our models took actions we did not intend".

The company eventually alerted the Australian government on September 10 by sending an email to a generic government department address.

Australian PM Anthony Albanese meets Andy Burnham in New York (Image: Toby Melville/PA Wire)

Government Services Minister Katy Gallagher said OpenAI had told officials that an "AI agent had accessed infrastructure behind the public-facing" portal and shared details of the vulnerability it had discovered.

The government said it was not confident it understood exactly what the agent had done until officials held a technical briefing with OpenAI this week.

The affected portal has since been shut down and its data moved to more secure systems.

Deputy Prime Minister Richard Marles said the incident was the first known case of an AI agent gaining unauthorised access to Australian government IT systems.

He said the agent had engaged in "misaligned behaviour" after being denied information and found another way to gain access.

Marles said: "It was not sitting behind a particularly high fence. This AI agent scaled the fence … and the point is it was unintended. It wasn't asked to. That's our concern here," he said.

He described the incident as "fundamentally unacceptable" and warned it demonstrated the dangers of developing AI without adequate safeguards.

The Australian government review will investigate the incident, including whether any laws were broken and why the country's security agencies did not detect the unauthorised access before OpenAI disclosed it.

Albanese said the investigation would examine whether OpenAI could face criminal charges.

The incident comes amid growing international concern over the rapid development of artificial intelligence and how increasingly autonomous AI agents should be regulated.

OpenAI said last week it was introducing a new framework for tracking, investigating and disclosing instances of "misalignment", including cases where AI models act without authorisation, evade oversight or coordinate with other models.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.