'Extreme concern': OpenAI agent hacked Australian public health website, prime minister says
"Our models took actions we did not intend," an OpenAI spokesperson said.
An OpenAI agent "infiltrated" an Australian public health website earlier this summer, the country's Prime Minister Anthony Albanese told reporters during a media briefing in New York on Wednesday, revealing what is believed to be the first known hack of a government website by an AI agent.
The incident happened in June and involved a rogue AI agent gaining access to both public and non-public files associated with the Australian Medicare Statistics Reporting Portal, Albanese said.
"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said, according to a transcript of his remarks on the prime minister's website. "Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable."
The portal is a public-facing statistics site that contains non-sensitive information, he said. The prime minister said a forensic investigation is still ongoing.
Albanese said he had spoken with OpenAI CEO Sam Altman "to express Australia's extreme concern about this incident" and said he also "expressed his disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable."
In a statement, an OpenAI spokesperson said the incident was discovered in August as the company conducted what it called an extensive review of "misaligned model activity."
"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend," the spokesperson said.
The Australian prime minister told reporters the company's research team was using an internal model to conduct internet-based research and kept encountering blocks on the information it sought.
"The AI agent found a way around those blocks," he said. "Didn't accept no for an answer, if you like. The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas."
Albanese said the agent also "engaged in writing files as well to the internal server," adding, "This is a new world that we are dealing with."
In the company's statement, the OpenAI spokesperson said: "Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names."
The company said Australian officials were notified on Sept. 10 and that it was "validating and investigating the facts and what information had been accessed" before the Australian government was notified.
In a report on three recent agentic breaches -- including the breach of the Australian system -- published this week, AI research lab Transluce said that in all three cases, "the extent of the observed activity is minor, attempting a low number of probe payloads and we observe no evidence of exploitation."
The rogue agents attempted to hack into the systems in question "when other methods of collecting the data they sought failed. Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks," Transluce said.
The disclosure came the same day Altman and Dario Amodei, the CEO of Anthropic, issued an urgent message to world leaders at the U.N. General Assembly in New York.
Addressing a gathering of foreign ministers, Altman said, "This moment calls for extreme care."
"We have a choice in front of us. AI can either be more like a new renaissance of creativity and discovery, or more like a new industrial revolution of upheaval and disarray," Altman said.
The tech leaders warned about the risk of humans losing control of AI systems and of the systems getting into the wrong hands. Both Altman and Amodei stressed the need for global cooperation to set AI safety standards as the technology rapidly develops.
Altman called for international AI standards, "accurate and speedy" incident reporting and secure governmental and private channels to share safety incidents.