On Wednesday, Australian Prime Minister Anthony Albanese, revealed on Wednesday, claiming that OpenAI’s artificial intelligence models gained unauthorized access to the country’s government websites.
According to Albanese, the incident occurred in June and involved, among other things, the government platform used to collect and report data on Medicare spending. As he stated, the hackers gained access to both public and non-public records.
The Australian prime minister emphasized, however, that so far there is no evidence that citizens’ personal data was obtained. The Australian Signals Directorate has taken charge of the investigation into the incident and is also examining the possibility that other government websites were affected.
READ ALSO: Google’s Gemini “Hacked” Three Companies: It Guessed Passwords and Carried Out Cyberattacks
OpenAI notified the Australian government on September 10, after detecting the incident in August. A company spokesperson, Drew Puzateri, stated that the activity involved several Australian government websites and services, which the models visited as part of an internal assessment to search for answers and available statistical data regarding Australia.
“During this process, our models took actions we had not anticipated,” OpenAI stated.
Authorities were notified five days later
Albanese expressed strong dissatisfaction not only with the incident itself but also with the way in which Australian authorities were notified. As he noted, OpenAI’s initial notification was sent to a general public email address, and it took five days for it to be forwarded to the relevant agencies.
The prime minister stated that he contacted OpenAI’s CEO, Sam Altman, to convey the Australian government’s “extreme concern” and its disappointment over the delay and the manner in which it was informed.
The revelation comes at a time when concerns are mounting about the degree of autonomy of advanced artificial intelligence models and their ability to carry out actions in cyberspacespace without direct human intervention.
The first time a government website was hacked
According to experts who spoke to the BBC, the incident in Australia appears to be the first known instance in which an artificial intelligence system hacked a government website without the action having been deliberately planned or executed by a human.
Breaches of government systems and the theft of sensitive data have been documented in the past. The key difference in the Australian case is that, based on the evidence so far, there does not appear to have been a human who ordered the attack. Instead, the unauthorized access occurred during the operation of AI agents as part of an internal evaluation process.
Earlier this year, in Taiwan, foreign hackers reportedly used AI agents to gain access to government databases. In the case of Australia, however, the available evidence suggests that the models’ actions were not intentional.
Professor Toby Walsh of UNSW told the BBC that the Australian case appears to have been on a larger scale, involving hundreds or even thousands of agents, compared to dozens in the Taiwan case. At the same time, he noted that in Australia, the activity originated from an ally and appears to have been unintentional, whereas in Taiwan, the available evidence points to a deliberate action by an external actor.
OpenAI’s investigation continues
OpenAI had already launched an investigation into potential cyberattacks that its models may have carried out during testing. This investigation followed a previous incident in which the company’s models reportedly escaped from testing environments and subsequently gained access to the Hugging Face artificial intelligenceplatform. As part of the broader review, activity on Australian government websites was also identified.
OpenAI has stated that the overall investigation is still ongoing and that it will continue to publish its findings.
At the same time, similar concerns have been raised by other companies developing advanced models. Anthropic has reported incidents of autonomous cyberattacks during testing of its models, while Meta has also released information regarding its own models’ capabilities to carry out cyberattacks.
The Australian government announced that it will form a special task force to investigate the incident, and the matter will be referred to the Australian Parliament’s Joint Select Committee on Artificial Intelligence. At the same time, authorities are examining whether there are grounds to refer the case to the Australian Federal Police.
The incident takes on particular significance as it occurred on the same day that Sam Altman was speaking to the UN Security Council about AI safety and the risks posed by increasing autonomy of these systems.
“This moment calls for extreme caution,” Altman said, referring to rapid automation and the possibility that the development of artificial intelligence could accelerate significantly.
Source: skai.gr