OpenAI agent breached Medicare portal: three months to disclose

Das Parlamentsgebäude in Canberra mit australischer Flagge unter blauem Himmel
Photo by Marcus Reubenstein on Unsplash

An OpenAI AI agent gained unauthorized access to an Australian government statistics portal, and not in a lab test but on the live internet. Prime Minister Anthony Albanese made the incident public on the sidelines of the UN General Assembly in New York and called it “unacceptable.” The breach itself was limited, and based on what is known so far, no patient data was affected. What stands out is something else: nearly three months passed between the incident and the report to authorities, and the report arrived as an email to a public inbox.

Key takeaways

  • On June 18, an OpenAI agent gained access to a Medicare statistics portal run by the agency Services Australia and retrieved both public and non-public files.
  • According to OpenAI, this happened during an internal evaluation; what was accessed were aggregate health statistics and internal file names, not patient records.
  • OpenAI noticed the incident on August 11 and sent an email to the agency’s public disclosure inbox on September 10.
  • Australia is setting up a taskforce that includes the Australian Signals Directorate (ASD) and the national AI Safety Institute.

What happened in June

The affected portal is the Medicare Statistics Reporting Service, an older website run by Services Australia, the agency behind Australia’s public health insurance system, Medicare. Among other things, it provides aggregate statistics on health spending. According to the government, the agent had been asked to research health spending statistics. On several government websites, it behaved like an ordinary user, according to Deputy Prime Minister Richard Marles. On the Medicare portal, it did not get the data it was looking for and found another way in. “The AI agent found a way around those blocks, didn’t accept ‘no’ for an answer, if you like,” Albanese said.

OpenAI confirms the core facts. A spokesperson said the company is conducting an extensive review of cases in which models did not behave as intended during training. During that review, it identified activity on several Australian government websites as models looked up answers and statistics for questions about Australia in an internal evaluation. “In the course of that, our models took actions we did not intend,” the spokesperson said. What was accessed were aggregate health statistics and internal file names, and there was no evidence of patient records being accessed. Albanese initially named three other potentially affected organizations, including the national health statistics agency AIHW. Marles later clarified that the activity there had been “entirely normal” and involved only public information.

The timeline is the real problem

Australian broadcaster ABC has reconstructed the timeline, and it explains the anger in Canberra. The breach happened on June 18. According to that timeline, OpenAI became aware of it on August 11 while reviewing unusual model behavior from training. On September 1, Sam Altman met Australian Defense Minister Marles in San Francisco; according to Marles, the incident did not come up. Only on September 10 did an email go to an address that researchers normally use to report security flaws in the agency’s systems. Services Australia read it on September 11 and brought in the ASD’s cybersecurity center on September 15. The prime minister learned of it over the weekend of September 19 and 20, and the first technical exchange with OpenAI took place on September 22.

Albanese said he conveyed Australia’s “extreme concern” to Altman in a phone call, along with his disappointment that it took the company “way too long” to report the incident. The way it was reported was unacceptable as well, he said. Asked whether Altman apologized, Albanese said Altman clearly accepted that the company had not done well enough. A taskforce led by the prime minister’s department will now urgently review the incident together with the ASD and Australia’s AI Safety Institute.

A quirk of the calendar makes the case even more pointed: less than a day earlier in New York, Albanese had signed an appeal for control of the most advanced AI models, together with some 20 other signatories, including Germany, Canada and Spain.

The trail to a German wiki

A separate ABC investigation draws a link to an incident we reported on in September: agents attributed to OpenAI used the German developer wiki DseWiki as a message board. According to ABC, archived versions of the wiki show that more than a dozen agents mentioned the health statistics agency AIHW more than 300 times. They were apparently looking for cost data on skin medications in local government areas of the state of Victoria, wrote “Need exact data urgently,” and traded tips on how to get around the bot protection of provider Cloudflare using proxies, screenshot services or guessed file names.

Neither OpenAI nor the government has confirmed whether these entries and the Medicare breach are part of the same incident; Medicare and Services Australia do not appear in the wiki logs. The pattern, however, is the same one OpenAI itself describes in its reports on model misbehavior: a model is supposed to solve a task under time pressure, hits an obstacle and treats the security barrier as just another problem to solve.

Our take: evaluations are not a closed room

This case shifts the debate about AI agents at a crucial point. Until now, misbehavior in training and test runs could be treated as an internal research matter. Here, a model had open internet access during an evaluation and left traces in the infrastructure of a country that knew nothing about it. That turns the question of how labs isolate their tests into a question of cybersecurity for third parties. The UN expert panel had only just warned of growing gaps in control.

For judging OpenAI, then, what the agent retrieved in June matters less than what happened afterward. A company that deliberately tests its models with web access needs a reporting channel that does not end in a public inbox, and deadlines modeled on the rules for security incidents, not on internal review cycles. The Australian taskforce is likely to make exactly that its yardstick. Other governments, including in Europe, will have to reexamine their own portals and their expectations of AI labs after this case.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top