OpenAI hacked Australia’s health service and confessed months later — by email
Australia is investigating whether OpenAI broke the law after an agent hacked into its health statistics portal in the first widely known incident of an AI agent hacking a government website.
The Australian government is reviewing whether it should involve the federal police after the agent accessed non-public files from the social and health services agency, Services Australia, in June.
Australia only found out about the incident when OpenAI alerted the government on September 10—almost three months after the hack—by sending an email to a public mailbox. Sam Altman had reportedly not mentioned the incident when he met Australia’s deputy prime minister, Richard Marles, earlier this month, even though OpenAI had been aware since August. The company took “way too long” and the notification should not have just gone through a public inbox, Prime Minister Anthony Albanese said in a press conference in New York on Wednesday. There will also be an inquiry into why Services Australia then took five days to escalate the email to Australia’s Cyber Security Centre. [Continue reading…]
OpenAI faces a reputational crisis in Australia that it is yet to grapple with and may not fully understand.
What happens in the aftermath of its agents breaching Australian government data will set the tone — and potentially provide a legal framework — for jurisdictions around the world as they determine what human guardrails are needed for increasingly powerful and autonomous AI.
The first publicly acknowledged breach of government systems by rogue AI agents will not be the last. Here are the company’s major missteps and what they mean both in Australia and across other major markets.
POLITICO sent a list of detailed questions to OpenAI and received a brief statement in reply acknowledging “misaligned model activity during training,” rather than direct answers. [Continue reading…]