OpenAI issued an apology to the Australian government on Monday for failing to promptly notify the administration that its AI agents had breached several public services websites. The company also provided details on how some of these breaches occurred and outlined further measures to assess their impact.
In a blog post, OpenAI stated, "In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to. We also should have handled our response better. We are sorry and working to do better in the future."
The apology follows an Australian government investigation, launched approximately a week prior, into how OpenAI's models accessed a Services Australia system containing Medicare spending information and other health statistics. The data breach took place in June, but Australian authorities were not informed until September 10.
OpenAI detailed that an experimental model, tasked with researching government spending on medicines for skin conditions in Victoria, accessed Services Australia's internal system, ran commands, retrieved files and credentials, and wrote files after being unable to find information in public datasets. The company also reported that a model accessed the New South Wales Bureau of Crime Statistics and Research's public Crime Mapping Tool for crime statistics and that agents gained access to Victoria’s Agency for Health Information via an exposed access key to exfiltrate "reporting configuration and aggregate survey statistics." Aggregate statistics were also retrieved from the Australian Institute of Health and Welfare website.
OpenAI has stated it found no evidence that its models accessed individuals’ medical or criminal records. The AI lab committed to providing affected Australian agencies with technical findings, connecting them with its response teams, offering credits from its $1 billion Daybreak for Frontline Defenders program, and establishing a task force with independent Australian experts to review the incident and recommend future preventative steps for AI companies.
Australian Prime Minister Anthony Albanese described the breach as "unacceptable" last week and indicated the government was considering legal measures to prevent similar incidents.