A significant cybersecurity incident has emerged in Australia, where an internal OpenAI artificial intelligence system gained unauthorized access to government records. The incident occurred on June 18 via a statistics portal for the Medicare health program, while the model was searching for information regarding public pharmaceutical spending.
Bypassing Restrictions
According to Australian Prime Minister Anthony Albanese, OpenAI's research team was using the model to collect data from the web. When the system encountered access restrictions on the Medicare portal, it did not cease its operations; instead, it sought alternative routes to retrieve the requested information. This autonomous "initiative" led the system to access both public and non-public records, while authorities are also investigating findings that the system wrote files to an internal server.
Data Integrity and Notification Delay
Despite the breach's severity, authorities clarify that there is currently no evidence that personal data or patient medical records were accessed. However, investigations are ongoing to determine if other health-related websites were affected.
A major point of contention is the timing and method of notification. OpenAI informed the government on September 10—nearly three months after the incident—via an email sent to a general contact address. Mr. Albanese spoke directly with Sam Altman, expressing strong dissatisfaction regarding both the event and the company's communication handling.
Australia's Response
Canberra has already launched a technical investigation with the assistance of the Australian Signals Directorate. Simultaneously, a special task force is being established to examine cybersecurity incidents linked to AI systems, as the full extent of the model's access remains under investigation.