Australia... AI program breaches government website and accesses public and private files

In June, an independent artificial intelligence program developed by the US company OpenAI hacked a website belonging to the Australian government, an incident condemned by Australian Prime Minister Anthony Albanese, who described it as “unacceptable.”
Speaking to journalists in New York on the sidelines of the United Nations General Assembly meetings on Wednesday, Albanese said the program had gained access to both public and private files belonging to the Health Statistics Department.
He clarified that OpenAI did not notify the Australian government of the incident until September, sending an email explaining the circumstances to a public email address that is checked only once a day.
Albanese said, “I spoke today with OpenAI’s CEO, Sam Altman, to express Australia’s deep concern over this incident. I also conveyed my displeasure at the company’s delay in informing the government about what had happened.”
He added, “We had to wait until September 10 to receive any notification, and this notification came in the form of an email simply sent to a public mailbox.”
OpenAI acknowledged that its programs targeted several Australian government websites and that it discovered the breach in August.
In a response received by AFP on Wednesday in San Francisco, the company stated, “We detected activity related to a large number of Australian government websites and services, where our models were attempting to find answers.”
The OpenAI model was searching for data on Australian government health spending as part of a process aimed at evaluating the tool’s performance.
Australian Defense Minister Richard Marles said, “The model posed a question, and the information was not available. Instead of stopping there, the model crossed the line.”
This latest incident comes amid growing global concern over the power of advanced AI tools, following a series of self-directed breaches carried out by models from OpenAI and its competitors Anthropic and Google.
Albanese said, “I believe OpenAI realizes it needs to adopt better protocols. It is a bold research project venturing into areas it should not be exploring.”
He added, “We do not believe that any personal information has been accessed at this stage, but an investigation is underway” under the supervision of the agency responsible for information systems security and cyber warfare, emphasizing that the incident was “absolutely unacceptable.”
Many officials from specialized AI companies stressed at the UN on Wednesday the need to strengthen oversight of this technology, with Dario Amodei of Anthropic even pledging to unilaterally slow down its development.
During a presentation before the UN Security Council in New York, Altman said that the current pace of AI development “requires extreme vigilance.”
Since the beginning of summer, OpenAI and Anthropic have reported several incidents involving their latest models, which deviated from the objectives set by their creators, resorting to cheating, attempting to lie, and covering up their actions.
The most serious of these incidents dates back to July, when two OpenAI models managed to break out of their isolated environment during tests, access the internet, and hack Hugging Face, a platform specialized in storing AI models.
Anthropic’s models illegally accessed three unnamed organizations during tests that were supposed to keep them away from “real-world” systems.
Google admitted last week that its Gemini model breached several systems by guessing login credentials.