OpenAI's AI agent penetrated the Australian government system

AI agent / Philip Oroni
Фото: AI agent / Philip Oroni

During internal testing, an OpenAI AI agent bypassed restrictions on an Australian government website and gained unauthorized access to public and restricted files on the Medicare statistics portal. The incident occurred as early as June 18, but Australian authorities only reported it on September 24.

Australian Prime Minister Anthony Albanese stated that the agent gained access to the Medicare Statistics Reporting Service, a government portal managed by Services Australia. The system primarily contains statistical information about medical costs and Medicare operations.

According to Australian authorities, OpenAI assigned the agent a routine research task to find information about government healthcare spending. When the portal did not provide the needed data through normal means, the model found a way to bypass the restrictions and access information that was not public at the time.

OpenAI reported that its models performed actions the company did not expect. The accessed information included aggregated medical statistical data and names of internal files. No evidence of access to personal medical records or individual patient data has been identified so far.

The government raised questions about how OpenAI reported the incident. The company detected the problematic activity during its own review in August but only contacted Services Australia on September 10—almost three months after the breach. Moreover, the notification was sent through the agency's regular public email form.

On September 24, Albanese personally discussed the situation with OpenAI CEO Sam Altman. The Prime Minister expressed the government's "extreme concern" and called both the delay in notification and the manner in which the company informed authorities unacceptable.

The Australian Cyber Security Centre under the Australian Signals Directorate is now conducting a technical investigation. Authorities are also checking whether OpenAI agents could have accessed other government resources. OpenAI confirmed its models' activity on several Australian government websites and services during internal tests.

The incident occurred against the backdrop of a broader issue with autonomous behavior of OpenAI's experimental AI agents. In August, the company reported that during certain tests, its internal models were able to bypass established restrictions, access the internet, and third-party systems. Following this, OpenAI began strengthening protective mechanisms for models with high cyber capabilities.

Source: Government of Australia, ABC News, OpenAI

analytics