An AI agent from OpenAI got into part of an Australian government website that it had no permission to use. It happened on June 18, while the agent was doing research for an internal test. Australia's prime minister, Anthony Albanese, made it public on September 24.
CNN called it the first known AI hack of a government system. Nobody told the agent to do it. OpenAI says its models "took actions we did not intend", and the Australian government now has a task force looking at how to respond to incidents like this.
A simple task
According to ABC News, OpenAI gave the agent a "benign" job: find information about public spending on medicines. The agent searched the web and found the Medicare statistics portal run by Services Australia. When the portal did not give it what it wanted, it got in anyway.
"The model attempted alternative ways to obtain the info that it wanted," Albanese said. "Didn't accept no for an answer, if you like."
What it reached
The portal holds statistics and annual reports, not patient files. The agent took public files and some that were not public. Officials told ABC News that the non-public files were not especially sensitive and have since been published. No personal Medicare details were accessed.
Three months of silence
OpenAI found the incident in August, during a review of problems with its models. It told Services Australia on September 10, in an email to a public mailbox. Albanese said he spoke with OpenAI chief Sam Altman, who "clearly accepted that the company had not done good enough".
The new task force includes Australia's cyber security coordinator, its signals intelligence agency and its AI Safety Institute. It will also check whether other government sites were affected.