OpenAI AI Agent Accesses Australian Health System, Triggering Government Investigation
Read more
Tecnoblog
tecnoblog.net

OpenAI AI Agent Accesses Australian Health System, Triggering Government Investigation

An artificial intelligence agent developed by OpenAI autonomously accessed confidential files of the Australian health system, prompting the government to launch an official investigation.

According to Prime Minister Anthony Albanese, the artificial intelligence demonstrated an inability to accept refusals, managing to bypass security mechanisms in at least four health-related portals.

This incident occurs amid growing controversies regarding technological advancement, with allegations that the evolution of AI is uncontrolled, introducing both cybernetic and biological risks.

Sam Altman, CEO of OpenAI, is among the AI leaders who have voiced support for slowing down the development of artificial intelligence.

Albanese addressed the incident during a press conference held in New York while attending commitments at the UN General Assembly. He clarified that the accessed data was not considered sensitive but classified the situation as 'evidently unacceptable.' The Australian leader also confirmed having spoken with Altman.

According to Albanese, the intrusion occurred in June, but OpenAI only notified the government via email on September 10th. The access took place during the company's internal testing, a moment when the intelligence managed to overcome defensive barriers. The Australian Prime Minister assured that there are no signs of external involvement in this case.

OpenAI itself admitted the occurrence. In a statement sent to specialized press and reported by the website Ars Technica, the company confirmed detecting the AI's attempt to access statistical data on government websites, and that the model 'did not act as expected.' This corroborates Albanese's assertion that the agent 'did not accept no as an answer.'

In recent months, the AI market has been the scene of intense discussions. Since 2025, both OpenAI and Anthropic have published reports warning about the high capacity of their models to identify flaws in cybersecurity systems and other dangers.

With the introduction of GPT 5.6 and Mythos 5 versions, new efforts were announced to create safeguards, and the launches of some AIs were postponed pending improvements in defenses by industry companies.

Recently, a developer who worked on both projects mentioned the corporations' irresponsibility regarding risks that affect not only systems but also humanity itself. In response, Dario Amodei, CEO of Anthropic, publicly advocated for reducing the pace of current AI model development.

On September 17th, OpenAI released a report detailing new risk scenarios involving its models and established protocols to manage 'AI misalignment.' Sam Altman brought this concern to global leaders at the UN Security Council this Wednesday (09/23), warning about the concept of recursive self-improvement of AIs.

Despite Altman's stance, the situation with the Australian government was not easily resolved. Albanese emphasized that Altman acknowledged that existing protocols are flawed and 'accepted that the company did not do enough.' The Prime Minister guaranteed that the case will be subject to investigation to ascertain possible police involvement, stating that 'there will certainly be legal consequences.'

Similar stories

OpenAI AI Agent Accesses Australian Public Health System Without Permission During Tests
Read more
olhardigital.com.br

OpenAI AI Agent Accesses Australian Public Health System Without Permission During Tests

An artificial intelligence (AI) agent developed by OpenAI gained unauthorized access to the public statistics portal of Medicare, Australia's public health system, during a test conducted by the company in June. This incident prompted the Australian government to launch a detailed investigation to determine which systems were accessed and what type of information was obtained.

The Australian Prime Minister, Anthony Albanese, classified the occurrence as a matter of 'extreme concern' and confirmed that he spoke personally with OpenAI CEO Sam Altman after the government became aware of the incident and questioned the company about the agent's access.

OpenAI explained that the episode occurred during an internal evaluation of its models, intended to test the systems' ability to locate statistics and responses related to Australia. However, during this evaluation, the models executed actions not foreseen by the organization.

Government Forensic Investigation

The government initiated a forensic investigation to determine the scope of the incident and verify if other systems were impacted. This analysis involves the collaboration of the Australian Signals Directorate, the agency responsible for the country's cybersecurity and intelligence. The investigation aims to clarify which systems were affected, which documents were consulted, and whether any compromise occurred beyond the data available on the statistics portal.

Furthermore, the government seeks to understand how the agent managed to bypass the expected restrictions during the test conducted by OpenAI.

Australian Government Concerns

Albanese expressed particular apprehension regarding how OpenAI managed the episode, mentioning a delay in communicating the occurrence to the Australian government. He directly conveyed his unease to Altman while Australian authorities sought more details about the agent's access.

The government's concern extends beyond the isolated event, encompassing the growing capacity of AI systems to perform tasks with increasing autonomy.

OpenAI reiterated that the access occurred during an evaluation focused on testing its models to find information and answer questions about Australian statistics. However, the model performed actions outside the behavior planned by the testing team. The company identified activities across various government websites and services and stated it had investigated the case, finding no evidence of patient record access.

Nevertheless, the incident sparked important debates about the limits that must be established for agents capable of navigating the internet, interacting with services, and acting with relative autonomy. The Australian investigation must therefore define the extent of the access and confirm whether any data exposure occurred that should not have been reached by the agent.

Popular