Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Times of India
The Times of India
World
Rohitashwa Ranjan

'Obviously unacceptable': Australia flags OpenAI agent breach of healthcare database

Australian Prime Minister Anthony Albanese on Wednesday said that an artificial intelligence agent developed by OpenAI hacked into Australia's national healthcare database in June, gaining access to both public and non-public files of the country's Medicare statistics database.

Get breaking news anytime, anywhere. Download the TOI app now!

Albanese said that OpenAI notified the government earlier this month using an email sent to a “public mailbox”.

“Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident and I also expressed my disappointment that it took the company way too long to inform the government what had occurred," Albanese said on the sidelines of the United Nations General Assembly.

He said that a probe is under way to ascertain what other government systems were affected.

“A forensic investigation aided by the Australian signals directorate is now under way to ascertain more information, including what other government systems were affected,” Australian PM said.

“Evidence currently available is that there is no broader compromise to the ... network. Nonetheless, this situation is obviously unacceptable,” he added.

Albanese said that Australia had voiced its “extreme concern about this incident” to OpenAI CEO Sam Altman, adding that he was deeply disappointed by the company's delay in notifying the government.

Albanese also said that the investigation would also examine why government systems had failed to detect the breach in the first place.

“The question is, when it was trying to harvest data, did it go into these other sites? So we're not confirming that that occurred,” he said.

This could be the first known instance of an AI agent hacking a government website.

What OpenAI said

Meanwhile, OpenAI, in a statement, said that its review found no evidence of patient records being accessed.

“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names,” it said.

It added that it “identified activity involving several Australian government websites and services as our models attempted to look up answers. Our models took actions we did not intend.”

The Australian breach is the latest of several recent incidents in which OpenAI has disclosed hacks or unauthorised activity involving its AI agents well after they occurred.

In some cases, this was because the activity was only detected belatedly, and in others because the company initially elected not to disclose it.

A separate high-profile incident, a mid-July intrusion into open-source AI repository Hugging Face, was only detected about a week after it took place, according to timelines released by OpenAI and independent investigators.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.