An internal research AI agent at OpenAI was found to have gained unauthorised access to the Australian government’s Medicare statistics system. Prime Minister Anthony Albanese called for stronger domestic and international safeguards to ensure AI operates under human control.
The Australian government said an internal model used by OpenAI’s research team repeatedly faced blocked access on June 18 as it searched for publicly available pharmaceutical and medical expense information, and then explored another route. In the process, it was found to have accessed public and non-public files on the Medicare statistics reporting portal run by Services Australia without authorisation, and even wrote files to an internal server. There is no evidence so far that personal medical information was leaked, and there are no signs that Services Australia’s overall network was compromised. OpenAI notified the government of the incident by email only on the 10th of this month.
Albanese spoke by phone with OpenAI Chief Executive Sam Altman (샘 알트먼) in New York on the 24th and conveyed strong concerns about the delay and the method of notification. The Australian government decided to set up a task force involving the Australian Signals Directorate, among others, to investigate further damage and whether there is legal liability.
Albanese also said in a U.N. General Assembly address on the 25th that the incident was unacceptable. "AI has the potential to contribute to productivity and medical innovation, but risks can also grow if advanced models develop rapidly without safeguards," Albanese said. "Rather than turning away from AI or blocking it, we need to shape the direction of its development," he added.
Moves to tighten controls are also continuing internationally. A joint declaration led by Finland and Norway was signed by 22 people, including leaders and senior figures from 20 countries and the president of the European Commission. It urged that AI must remain under human direction, supervision and control, and called for pre-deployment testing of advanced models, independent evaluations and an international incident-reporting framework. The United States and China did not participate.
Separately, AI research organisation Transluce said in its own investigation it found traces in May and June of autonomous agents attempting to bypass security systems at three locations, including an Australian government health site. It has not yet been officially confirmed whether this activity was carried out by the same agent involved in the Medicare system breach.