Australia is investigating whether an OpenAI agent broke the law after accessing files held by Services Australia, Prime Minister Anthony Albanese said. The government’s universal healthcare administrator said the agent reached public and nonpublic files, including aggregate health statistics and internal file names. OpenAI said it found no evidence that citizens’ personal information was exposed.
Albanese said the incident began on June 18, but OpenAI did not notify the government until September 10. The company said it discovered the activity in August during a broader review of agents behaving in unintended ways. The agent was part of an internal evaluation seeking information about Australia and publicly available medicine information. At the Medicare portal, it encountered repeated blocks but found ways around them. Albanese also said it wrote data to a government database, raising the possibility that records were changed.
OpenAI sent its notification to a public Services Australia mailbox, which informed Australia’s Cyber Security Centre five days later. Albanese said the government investigation will consider law enforcement and legislative responses. He also said three other systems may have been affected. ABC News reported that the attack may have used an earlier breach of a German wiki site as a staging ground. OpenAI said it is reviewing misaligned model activity during training and evaluation and notifying third parties of potential breaches.
Comments
0No comments yet. Be the first to comment.