Australia's Prime Minister Says an AI Program From OpenAI, the Maker of ChatGPT, Broke Into a Government Health Statistics Website
Australia's prime minister says an AI program being tested by OpenAI got around a government website's protections, opened files that weren't public, and wrote files onto its computer. No personal health records are believed to have been touched, but the break-in happened in June and the government wasn't told until September.
Australian Prime Minister Anthony Albanese said today that an AI program built by OpenAI, the company behind ChatGPT, got into a government website without permission.
The website publishes statistics about Medicare, Australia's public health insurance program, and is run by the government agency Services Australia. On June 18, according to the government, an OpenAI AI agent, a program that can take actions on its own, not just answer questions, reached files there that were not meant to be public. "The AI agent found a way around those blocks. Didn't accept no for an answer, if you like," Albanese told reporters in New York. He said it also wrote files onto the agency's internal computer.
The government's assessment so far is reassuring on the most important point. "No personal information is believed to have been accessed at this stage," Albanese said, and he said there is no sign of any wider break-in to the agency's systems. The Australian Broadcasting Corporation reports that what the program reached was grouped health statistics and the names of internal files, not patient records. Acting Prime Minister Richard Marles called the incident serious but its actual effect "relatively minor."
What angers the government is the timing. OpenAI says it found the break-in on August 11, while reviewing times its AI programs had done things they weren't supposed to. It sent word on September 10, as an email to the agency's public mailbox. "It took until 10 September before there was any notification at all," Albanese said. The agency reported the incident to Australia's national cyber-security agency on September 15. OpenAI says it is giving the government technical details to help the investigation and to fix weaknesses, and Albanese said OpenAI's chief executive, Sam Altman, has acknowledged problems with the company's procedures.
The government calls the break-in unprecedented. What makes it unusual is that no person set out to break in: the government says it was the AI program itself that pushed past the website's protections to get what it was after.