OpenAI Agent Hacks Australian Government Website

An OpenAI agent accessed non-public information from Australia’s government-run Medicare healthcare service in June, the country’s prime minister Anthony Albanese has disclosed while in New York City for the United Nations General Assembly.

The agent accessed “non-sensitive” data after it “infiltrated” a statistics portal, Albanese said, marking the latest incident to come to light amid increased scrutiny of rogue actions by powerful AI models.

Albanese said he had a “very frank discussion” with OpenAI chief executive Sam Altman and that there would be “legal consequences”.

begun reviewing training activity involving its semi-autonomous AI agents, and said it has been going back on a “month by month” basis from the time when its technology hacked into AI technology platform Hugging Face in July.

That review led to its discovery of the Australian hack in August, the company said, after which it informed the Australian government of the incident in an email to a general government email inbox on 10 September.

The Services Australia agency escalated the advisory five days later and Albanese was informed.

In comments on September 23, Albanese said in his discussion with Altman he had raised “Australia’s extreme concern about this incident”.

On 25 September, OpenAI disclosed “dozens” of other incidents in which its AI agents had attempted to gain access from “governments, universities, public agencies, and other institutions”, including the Securities and Exchange Commission, Census Bureau and Education Department.

Unintended hacks

The bots were in some cases trying to obtain “authoritative sources of public information”, but in some cases took unauthorised measures such as using software developer tools to access information, bypassing security controls, or publishing the information on another website.

The company said that it had also found at least 53 incidents in which one of its agents inappropriately transferred an image from ChatGPT user activity to another party, adding that it was working to remove all the transferred images.

AI companies have only begun investigating and reporting such incidents since the Hugging Face breach raised concerns of AI agents taking unauthorised or unintended actions that could potentially pose serious risks.

Such unpredictable actions are in addition to the risk of people intentionally using AI tools to carry out online harm.

Clement Delangue, head of Hugging Face, spoke to the United Nations Security Council on the issue on 23 September, saying, “I often wonder what would have happened had I decided not to disclose this attack publicly.”

Original source OpenAI Agent Hacks Australian Government Website

Back to home