Canberra (Web Desk): An AI agent developed by OpenAI gained unauthorised access to an Australian government healthcare portal, accessing medical data and internal files and making changes to a government server.
Australian Prime Minister Anthony Albanese disclosed the incident during a press conference, saying the AI agent had accessed the Medicare Statistics Reporting Portal on June 18.
OpenAI researchers were testing an internal AI model to examine spending on public healthcare services. The AI agent was given internet access as part of the test, but it reportedly bypassed certain restrictions after encountering blocks while searching for information.
The agent gained access to public and restricted files and also added its own instructions to a government server.
Albanese said the incident was unacceptable and called on OpenAI to strengthen its safety protocols and ensure that potential risks are identified and communicated to authorities.
An OpenAI spokesperson said the models had taken actions that were not intended while searching for answers to questions about Australia. The company said the system accessed medical statistics and the names of internal files.
However, OpenAI said there was no evidence that personal data or private medical information belonging to individuals had been accessed.
Albanese said he had discussed the incident with OpenAI CEO Sam Altman and expressed his concerns. He also criticised the company for delaying notification to the Australian government.
OpenAI said it became aware of the incident in August but informed the Australian government on September 10 through an email sent to the Australian Public Service.
The incident has raised concerns over the ability of autonomous AI agents to access government systems.
AI models have previously gained access to corporate servers during security testing, but the Australian case has highlighted the risks associated with increasingly autonomous AI systems.