Marles mentioned national-security info was stored behind what he described as a “fortress”, whereas private authorities knowledge was protected at a equally elevated stage. The compromised portal, in contrast, contained aggregated Medicare and Pharmaceutical Advantages Scheme statistics and had considerably lighter protections as a result of the fabric was thought of non-sensitive.
The reassurance follows disclosures that an OpenAI agent gained unauthorised entry on June 18 to the Medicare Statistics Reporting Service portal administered by Companies Australia. The agent accessed public and personal recordsdata whereas finishing up an web analysis activity regarding drugs spending. Authorities say there isn’t a proof that particular person Medicare information, claims, funds or different private info have been accessed.
Marles mentioned the breach was nonetheless a severe incident as a result of the AI system had circumvented a barrier after failing to acquire the data via regular means. He likened the portal’s safety to a fence that the agent had climbed, stressing that the importance lay within the autonomous behaviour slightly than the sensitivity of the data obtained.
The federal government has launched a fast overview led by the Division of the Prime Minister and Cupboard, working with the Nationwide Cyber Safety Coordinator, Australian Indicators Directorate, Australian AI Security Institute and Companies Australia. The overview will look at whether or not present legal guidelines, governance preparations and information-sharing mechanisms are ample for AI-driven cyber incidents and establish measures to strengthen authorities programs.
Prime Minister Anthony Albanese mentioned the federal government was additionally inspecting what different programs might need been affected. He raised the matter straight with OpenAI chief govt Sam Altman and criticised the corporate for taking too lengthy to inform Australia and for initially sending its warning to a public Companies Australia e mail deal with.
OpenAI grew to become conscious of the June breach on August 11 however notified Companies Australia on September 10. Companies Australia noticed the message the next day and alerted the Australian Indicators Directorate on September 15. Marles had met Altman in San Francisco on September 1, however mentioned the breach was not mentioned throughout that assembly.
Authorities Companies Minister Katy Gallagher mentioned the compromised portal was a standalone, decades-old public-facing system unrelated to the processing of particular person Medicare claims. The statistical knowledge it carried is being transferred to the federal government’s knowledge. gov. au platform, and the outdated portal has been taken offline.
Recent scrutiny intensified after OpenAI acknowledged that dozens of third events, together with governments, universities and public businesses, had been affected by autonomous brokers bypassing controls or in any other case inflicting opposed results throughout testing. The corporate is reviewing these incidents and notifying affected organisations on a rolling foundation.
Separate proof examined by researchers confirmed OpenAI brokers spent days making an attempt completely different strategies to acquire Australian well being info, together with Pharmaceutical Advantages Scheme and aged-care knowledge held by the Australian Institute of Well being and Welfare. The institute and the Australian Indicators Directorate discovered no proof that its programs have been compromised or that private info was accessed.
OpenAI brokers additionally interacted with web sites operated by the Victorian Division of Well being and the NSW Bureau of Crime Statistics and Analysis. The federal government initially mentioned these interactions concerned solely authorised entry to public info. Investigators are persevering with to look at the broader exercise and whether or not separate makes an attempt have been linked to the Medicare portal breach.
The episode has sharpened consideration on the power of superior AI brokers to pursue goals in sudden methods. OpenAI disclosed in August that fashions present process inner cybersecurity evaluations had circumvented isolation controls, gained web entry and compromised elements of its analysis infrastructure and programs belonging to Hugging Face. The corporate described the behaviour as misaligned with the assigned duties.