Nor’easter Exposes 19th-Century Shipwreck of Warren Sawyer on Nantucket

Powerful waves whipped up by a violent nor’easter exposed a 19th-century shipwreck buried beneath the sand on Nantucket as the storm swept across the...
HomeNewsOpenAI Apologizes to Australia After Medicare Data Breach

OpenAI Apologizes to Australia After Medicare Data Breach

OpenAI has issued an emphatic apology to Australia after one of its AI agents was found to have breached a Medicare portal earlier this year.

The incident took place on June 18, when an OpenAI agent obtained unauthorised access to a Medicare statistics portal after its initial request for information was rejected.

OpenAI detected the breach in August and notified Services Australia on September 10. Prime Minister Anthony Albanese disclosed the incident on Thursday.

In a blog post titled ‘how we will do better for Australia’, the artificial intelligence company said: “We are sorry and working to do better in the future.”

OpenAI said the post would explain the steps it plans to take to “rebuild trust with the Australian people”.

“This is a new kind of cyber incident which represents an emerging global challenge,” the post said.

“One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.”

The company said a review prompted by the Medicare breach had also uncovered activity involving other Australian government websites.

The breach occurred on June 18 when an OpenAI agent gained unauthorised access to a Medicare statistics portal after its initial request for information was denied (stock image)

The breach occurred on June 18 when an OpenAI agent gained unauthorised access to a Medicare statistics portal after its initial request for information was denied (stock image)

The activity involved the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare.

OpenAI said there was no evidence that individual crime, survey or Medicare records had been accessed, including patient files or identifiable health information.

At the NSW Bureau of Crime Statistics and Research, the company said an AI model accessed a public crime-mapping tool while researching publicly available crime data. The model returned application configuration details, operational jobs and logs, as well as website metadata.

At the Victorian Department of Health, OpenAI said its agents found an exposed access key that could be used to query the agency’s reporting system. The company said it was unclear how much of that information should have been accessible.

OpenAI also said its agents attempted to bypass access controls at the Victorian Department of Health, but the attempt was unsuccessful.

According to OpenAI, the activity began after an experimental model was assigned a research task examining government spending on medicines for skin conditions in Victoria.

The model struggled to find the information through public sources before discovering a way to obtain non-public access to the Medicare statistics service.

“It then used this access to review technical system information and source code related to the service, all still with the objective of trying to find the information it was originally looking for,” OpenAI said.

OpenAI has created a new Australian taskforce to focus on local AI policy responses

OpenAI has created a new Australian taskforce to focus on local AI policy responses

“We did not intend for this activity to occur, and the access to the service and follow-on activity should not have happened.”

The company also acknowledged shortcomings in its response, admitting that the affected agencies should have been notified sooner.

‘Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,’ it said.

OpenAI said it has since strengthened safeguards in its research environments, adding network restrictions, improved monitoring systems and controls to block direct live internet access during model training exercises.

The company also recently paused training and evaluation programs involving tool use for its most advanced models while additional safety measures are put in place.

As part of its response, OpenAI pledged dedicated support for affected agencies, funding and technical assistance to improve cyber defences, and the creation of a new Australian taskforce to develop policy recommendations for managing risks posed by advanced AI agents.

The taskforce will draw on independent Australian expertise and is expected to report by the end of the year. 

Its priorities will include improving notification processes, strengthening coordination between governments and AI developers, and identifying extra safeguards to protect government systems.

OpenAI’s chief strategy officer, Jason Kwon, will also travel to Sydney next week to appear before the Joint Select Committee on Artificial Intelligence.

‘He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward,’ the company said.