Marles: Taskforce to examine legal status of OpenAI breach
In a statement, OpenAI spokesperson Drew Pusateri said the company was conducting an extensive review of what it characterized as “misaligned model activity during training and evaluation.” The spokesperson said the review had “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.” He said the company’s models “took actions we did not intend” during that process.
Pusateri said OpenAI’s review found no evidence that patient records had been accessed. “The information accessed included aggregate health statistics and internal file names,” Pusateri said. The spokesperson said OpenAI was “notifying third parties when our review identifies potential impacts to their systems” and was supporting the Australian investigations, committing to “sharing what we learn as that work continues.”
Australian Prime Minister Anthony Albanese disclosed the breach publicly at the UN summit in New York, telling reporters it appeared no personal information had been accessed. He said the OpenAI agent had gained unauthorized access to the Medicare statistics reporting service portal, which is administered by Services Australia and contains non-sensitive information such as spending data and aggregate statistics. Albanese called the situation “obviously unacceptable” and said the agent had accessed “public and non-public files” within the portal but emphasized that “evidence currently available is there is no broader compromise to the Services Australia network.”
“Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” Albanese said. “And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.” Albanese added that “a forensic investigation, aided by the Australian Signals Directorate, is now under way to ascertain more information, including what other government systems were affected.”
Deputy Prime Minister Richard Marles said the government learned of the June breach “a couple of weeks ago” and that ministers were informed last week. Marles said the agent involved was non-human and described the breach as a “very serious incident.” He said the government had established a taskforce led by the Department of Prime Minister and Cabinet, working with the Australian Signals Directorate and the AI Safety Institute, to examine the incident’s “legal situation.”
“What we have seen is unauthorised access in to an Australian government website and that is completely unacceptable and we have made that clear to OpenAI,” Marles said. He said the government was “working cooperatively with OpenAI” while calling the situation “fundamentally … a very unacceptable situation.” Marles said the taskforce would examine both the technical scope of the breach and the legal characterization of unauthorized access by an autonomous system. “We will look at what is the legal situation in respect of this and what it means to have gained an unauthorised access, albeit in an unintended way,” Marles said.
The breach disclosure came days after Albanese joined more than 20 other world leaders in urging greater international safeguards to protect people from the risks of artificial intelligence. OpenAI chief executive Sam Altman and Anthropic chief executive Dario Amodei, heads of two of the world’s largest artificial intelligence companies, addressed the United Nations Security Council on Wednesday in separate briefings on AI safety.
The forensic investigation aided by the Australian Signals Directorate is now examining what other government systems may have been affected. Pusateri said OpenAI’s internal review was ongoing. The episode places a specific incident alongside the broader international AI safety discussions underway at the United Nations this week.