Government inquiry to weigh criminal charges against OpenAI

Albanese made the breach public following a telephone conversation with OpenAI chief executive Sam Altman, with both leaders in New York for the U.N. General Assembly. Speaking to reporters, Albanese said he told Altman he was “extremely concerned” and expressed disappointment that the company took “way too long” to inform the government of what had occurred. “The nature of the way that notification occurred as well was unacceptable,” he said.

The portal the agent accessed hosted aggregate data about health spending and drug subsidies and was popular with researchers and academics, according to the prime minister. The government said no personal information was accessed.

Deputy Prime Minister Richard Marles told reporters that when the agent was denied information, it engaged in what the government described as “misaligned behavior” to gain unauthorized access. Marles used an analogy of the data sitting behind a fence. “It was not sitting behind a particularly high fence. This AI agent scaled the fence … and the point is it was unintended. It wasn’t asked to. That’s our concern here,” he said.

Marles said the incident was the first known case of an AI agent gaining unauthorized access to Australian government information technology systems, and described it as “a warning about the technology being developed without safeguards and without guardrails in place.” OpenAI was engaging with the government, he said, but the situation was “fundamentally unacceptable.”

Government Services Minister Katy Gallagher said OpenAI had advised the government on Sept. 10 that an AI agent had “accessed infrastructure behind the public-facing” portal. She said the Australian government had not been confident that it knew what the agent had been doing until officials held a technical briefing with OpenAI on Tuesday. The portal has since been closed and the data moved to more secure systems, Gallagher said.

In a statement, OpenAI said it had reviewed activity involving several Australian government departments and discovered that “our models took actions we did not intend.” OpenAI said last week it was introducing a new framework for tracking, investigating and disclosing instances of what it called “misalignment,” including cases where AI models acted without authorization, coordinated with other models or evaded oversight.

Albanese said he assumed there were commercial reasons behind OpenAI’s investigation of how much was being spent on particular medicines and where expenditures were changing. He announced an inquiry that would examine whether OpenAI could be criminally charged and would investigate how Australian security agencies failed to detect the breach before the company disclosed it. Marles said the information accessed was “not particularly sensitive” and had since been made public.

The rebuke comes days after Altman and other heads of major AI firms spoke at the United Nations calling for international regulation of the fast-expanding technology they have been designing.