
By Lucinda Garbutt-Young and Will Nicholas in Canberra
An OpenAI agent’s breach of a Medicare website is “very novel” and warrants the government’s significant response, a senior MP says after claims the hack has been blown out of proportion.
Cybersecurity experts have accused the federal government of overreacting and politicising an OpenAI agent breach of the Medicare Statistics Reporting Portal.
Public Service Minister Katy Gallagher rejects the claims.
“This was a significant issue. Yes, it was on a public-facing website, and the data that the agent accessed was not personal information or some of those datasets that we protect to the highest level – but it was very novel,” she told Nine’s Today program.
“We did the right thing, which was to come out and tell people what we knew.”
The government first learned about the breach through an email sent by OpenAI to an inbox only monitored once a day.
Senator Gallagher said it had since been moved to a centre within the department that monitors cybersecurity risks around the clock.
It is the first known time an AI agent has acted on its own, without the authority of a parent company, to access an Australian government data system.
The rogue agent has prompted experts to sound an alarm across the AI sector, which could completely take over corners of the internet in a matter of months.
Canberra has been scrambling to fortify digital infrastructure, but something more fundamental needs to change in AI behaviour, cybersecurity expert Chetan Arora told AAP.
He compared autonomous AI models to dogs being trained not to leave a yard.
“Either I can train my dog by means of punishment and reward for not crossing the boundary of my home, the second way is actually putting the fence and deterring the dog,” Dr Arora said.
“What was missing in these systems is this engineering approach of building the fence.”
The Monash University researcher said the Medicare breach was better classified as a permissions problem than a hack, because the bot in question was probably not told to stop when it hit a barrier like the one it ended up scaling.
“The agent was given a benign task of doing a research problem on medical spending, it hit a roadblock and it tried to improvise a way of getting around,” he said.
OpenAI has stressed it did not direct its agent to infiltrate the website in order to perform the innocuous research task it had been set.
The bot interacted normally with three Australian federal and state government sites, but broke into the Medicare statistics portal when offered resistance.
Policing autonomous agents did not require a human watching a model’s every move, but there needed to be a clear framework with flesh-and-blood input and stringent reporting obligations, Dr Arora said.
A task force set up after the breach to examine AI reporting obligations and Australia’s cyber-safety and legal avenues for punishing OpenAI is expected to report in a matter of weeks.
News all day, every day at CityNews.com.au.
Who can be trusted?
In a world of spin and confusion, there’s never been a more important time to support independent journalism in Canberra.
If you trust our work online and want to enforce the power of independent voices, I invite you to make a small contribution.
Every dollar of support is invested back into our journalism to help keep citynews.com.au strong and free.
Thank you,
Ian Meikle, editor

Leave a Reply