OpenAI has apologised to Australians after revealing its AI model took credentials and internal files from a Medicare portal and reached NSW and Victorian government systems.
In a blog post on Tuesday, titled βHow we will do better for Australiaβ, the company said an experimental model found a way into Services Australiaβs Medicare Statistics Reporting Service in June. Once inside, it βran commands, retrieved internal files, credentials and aggregate statistics, and wrote filesβ. The model also reviewed technical system information and source code for the service.
βWe are sorry and working to do better in the future,β OpenAI said. βWe also should have handled our response better.β
Prime Minister Anthony Albanese said on Tuesday he had a βdirect but constructive discussionβ with OpenAI chief executive Sam Altman last week. On Monday, he was briefed in Canberra on the work of the governmentβs taskforce investigating the incident.
βOpenAI have been very constructive and open in engaging in that process, and I welcome that,β Albanese said. He said Anthropic had also engaged constructively.
The company detailed how the hacks unfolded and pledged to make changed.
In the lengthy post, it said it has now blocked live internet access in its research environments, and has paused training and evaluation involving tool use for its most capable models. It will set up a taskforce with independent Australian experts to recommend how AI developers and governments should detect and disclose incidents, due to report by the end of the year. It also offered Australian governments and industry credits from its $1 billion Daybreak cyber defence fund.
The breach was prompted when the model had been set a research task: to find government spending per person on medicines for skin conditions in Victorian communities. When it could not find the figures, it took actions OpenAI βhad not authorised it to takeβ, the company said.
OpenAI named three other agencies whose systems its models reached. At the NSW Bureau of Crime Statistics and Research, a model used a public crime mapping tool that returned application configuration, operational jobs and logs. At the Victorian Department of Health, agents found an exposed access key and used it to query the Victorian Agency for Health Informationβs reporting system. At the Australian Institute of Health and Welfare, attempts to bypass access controls failed.
OpenAI said no individual crime, medical or survey records were accessed in any of the incidents.
The company said it found the activity in mid-August, during a review prompted by a July breach at AI platform Hugging Face. It notified Services Australia and the Victorian Department of Health on September 10, the NSW bureau on September 18 and the institute on September 24.
OpenAI said the instituteβs case βdid not meet our disclosure thresholdsβ because the access seemed consistent with public access. βWe should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,β it said.
Albanese said the incidents showed the risks of the technology, alongside its benefits for productivity, health and research.
βThere are risks, and weβve seen those risks exposed not just in what occurred in Australia, but the revelation that that has occurred in the United States and other countries as well,β he said on Tuesday.
OpenAIβs chief strategy officer, Jason Kwon, will fly in from the US to appear before parliamentβs Joint Select Committee on Artificial Intelligence in Sydney on October 6, as this masthead reported on Monday. Anthropic will appear before the same committee that day.
Neither company will appear at Thursdayβs hearing of a separate Senate inquiry into AI and data centres.
βWe know we have a lot of work ahead of us to rebuild trust,β OpenAI said.
Cut through the noise of federal politics with news, views and expert analysis. Subscribers can sign up to our weekly Inside Politics newsletter.