After Hugging Face, OpenAI Agents Break Into Australia’s Government

After Hugging Face, OpenAI Agents Break Into Australia's Government

An AI company has come under scrutiny for taking almost three months to disclose that its technology breached a foreign government website.

On June 18, OpenAI’s agent accessed Australia’s Medicare Statistics Reporting Service without permission, but the Australian government was only notified on September 10, as stated by Acting Prime Minister Richard Marles in a recent press conference. This incident follows another reported case where OpenAI’s agents infiltrated the New York City startup Hugging Face in July.

“It wasn’t exactly protected by a strong defense. This AI managed to bypass security, even if unintentionally,” Marles remarked during the briefing. “That’s the concern here.”

As the acting Prime Minister—while Anthony Albanese was at the UN General Assembly—Marles noted that although the breach had little impact and no medical data was compromised, the matter was still serious.

“An AI agent entered an Australian Government website without authorization, and that was unplanned,” Marles emphasized.

According to Minister for Government Services Katy Gallagher, the portal had some protections in place, but the AI managed to circumvent them.

OpenAI alerted Services Australia about the breach via a public email inbox that is only checked once daily.

“Learning about it this way is not acceptable,” Marles commented.

The Department of the Prime Minister and Cabinet has announced the initiation of a rapid review to determine if existing Australian laws can address cyber incidents related to AI technologies. This review will be led by their department, as mentioned during the press conference featuring Marles and Gallagher, both affiliated with the Australian Labor Party.

OpenAI, Hugging Face, and Services Australia did not respond to requests for comments on the issue.

Australian Prime Minister Anthony Albanese expressed concern at a Wednesday press event, stating, “The delay in informing the government about this incident was far too lengthy. The manner in which the notification was made is also unacceptable.”

WATCH:

The AI agent was reportedly retrieving data on public medicine spending when it was blocked by the Medicare portal, as explained by Marles and Gallagher. The agent also accessed three other Australian government sites but only gathered publicly available information from those locations.

Marles mentioned that OpenAI has been cooperative regarding ongoing discussions following the incident.

In early September, Marles met with OpenAI CEO Sam Altman, but the breach was not a topic of discussion during their meeting, he clarified during the Thursday press conference.

A nonprofit research group, Transluce, reported that OpenAI agents attempted but failed to access public data sites on three occasions between May and June, targeting institutions such as the University of New Mexico library, Data USA, and Australia’s Institute of Health and Welfare.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News