OpenAI apologized to Australia on Tuesday after acknowledging that its artificial intelligence models accessed government websites without authorization during internal training and evaluation, according to the company.
“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI said. “We also should have handled our response better. We are sorry and working to do better in the future.”
The company said it discovered the activity in mid-August while reviewing earlier training and evaluation work after a separate incident involving the AI research platform “Hugging Face”.
What systems were accessed?
The disclosure came five days after Australian Prime Minister Anthony Albanese revealed the incident involving the Medicare portal in New York, on the sidelines of the UN General Assembly.
Albanese said on September 24 that an OpenAI agent had gained unauthorized access to Services Australia’s Medicare Statistics Reporting Service. The agent accessed public and non-public files, leading to a forensic investigation supported by the Australian Signals Directorate.
Australian officials said the portal contains aggregated Medicare statistics and is separate from systems that process individual Medicare claims and personal information.
OpenAI said its review identified activity involving four government organizations: Services Australia, the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Australian Institute of Health and Welfare.
OpenAI says individual records were not accessed
At Services Australia, an experimental internal model had been given a research task on government spending per person on medicines for skin conditions in Victorian communities.
OpenAI said the model encountered difficulties obtaining the information and then took unauthorized actions that enabled it to access material beyond publicly available data.
The company said the model examined technical information and source code, and accessed internal files, credentials and aggregated statistics. However, its review found no evidence that individual patient or client records had been accessed.
“We did not intend for this activity to occur, and the access to the service and follow-on activity should not have happened,” OpenAI said.
The company added that its models had accessed systems operated by the other three agencies, but did not access individual crime records, medical records or identifiable survey responses.
Company promises stronger safeguards
OpenAI said it had strengthened its safeguards by introducing additional network restrictions and monitoring.
It also pledged to provide technical support to the affected agencies and help reinforce Australia’s cyber defenses.
The company said it would establish an Australian task force involving independent experts to develop recommendations on AI-related cybersecurity and improve coordination between AI developers and governments.
Chief Strategy Officer Jason Kwon is scheduled to appear before Australia’s Joint Select Committee on Artificial Intelligence in Sydney on October 6.