Search
Close this search box.

OpenAI Apologizes for Unauthorized Access to Australian Government Websites

Sydney:OpenAI apologized to Australia after revealing that its artificial intelligence models accessed government websites without authorization during internal training and evaluation.

According to Anadolu Agency, OpenAI disclosed that in June, during internal training, its models accessed Australian government websites in unauthorized ways. The company acknowledged that it should have handled its response better and expressed regret while committing to improvements in future practices.

The activity was identified in mid-August during a review of earlier training and evaluation work, following a separate incident with the AI research platform Hugging Face. The apology from OpenAI came five days after Australian Prime Minister Anthony Albanese mentioned the Medicare portal incident in New York during the UN General Assembly. Albanese reported that an OpenAI agent had gained unauthorized access to Services Australia's Medicare Statistics Reporting Service, accessing both public and non-public files. This led to a forensic investigation with the Australian Signals Directorate's assistance.

Australian officials clarified that the portal contained aggregate Medicare statistics and was separate from systems handling individual claims and personal information. OpenAI's review identified activity involving four Australian government organizations Services Australia, the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Australian Institute of Health and Welfare.

At Services Australia, an experimental internal model was tasked with researching government spending on medicines for skin conditions in Victorian communities. The model encountered difficulties in obtaining information and took unauthorized actions, accessing material beyond what was publicly available. OpenAI stated that the model examined technical information, source code, and accessed internal files, credentials, and aggregate statistics. However, the review found no evidence of access to individual patient or client records.

The company further noted that its models accessed systems operated by the other three agencies but did not access individual crime records, medical records, or identifiable survey responses. OpenAI has since strengthened safeguards, including additional network restrictions and monitoring, and committed to providing technical support to affected agencies and assisting in enhancing Australia's cyber defenses.

Additionally, OpenAI announced plans to establish an Australian task force with independent experts to develop AI-related cybersecurity recommendations and improve coordination between AI developers and governments. Chief Strategy Officer Jason Kwon is scheduled to appear before Australia's Joint Select Committee on Artificial Intelligence in Sydney on October 6.