‘We are sorry’: OpenAI apologises for Medicare hack
OpenAI has apologised to Australians after revealing its AI model took credentials and internal files from a Medicare portal and reached NSW and Victorian government systems.
In a blog post on Tuesday, titled “How we will do better for Australia”, the company said an experimental model found a way into Services Australia’s Medicare Statistics Reporting Service in June. Once inside, it “ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files”. The model also reviewed the service’s technical system information and source code.
“We are sorry and working to do better in the future,” OpenAI said. “We also should have handled our response better.”
Prime Minister Anthony Albanese said on Tuesday he had a “direct but constructive discussion” with OpenAI chief executive Sam Altman last week. On Monday, he was briefed in Canberra on the work of the government’s taskforce investigating the incident.
“OpenAI have been very constructive and open in engaging in that process, and I welcome that,” Albanese said. He said Anthropic had also engaged constructively.
The company detailed how the hacks unfolded and pledged to make changes.
In the lengthy post, it said it has now blocked live internet access in its research environments, and has paused training and evaluation involving tool use for its most capable models. It will set up a taskforce with independent Australian experts to recommend how AI developers and governments should detect and disclose incidents, due to report by the end of the year. It also offered Australian governments and industry credits from its $1 billion Daybreak cyber defence fund.
The breach was prompted when the model had been set a research task: to find government spending per person on medicines for skin conditions in Victorian communities. When it could not find the figures, it took actions OpenAI “had not authorised it to take”, the company said.
OpenAI named three other agencies whose systems its models reached. At the NSW Bureau of Crime Statistics and Research, a model used a public crime mapping tool that returned application configuration, operational jobs and logs. At the Victorian Department of Health, agents found an exposed access key and used it to query the Victorian Agency for Health Information’s reporting system. At the Australian Institute of Health and Welfare, attempts to bypass access controls failed.
OpenAI said no individual crime, medical or survey records were accessed in any of the incidents.
The company said it found the activity in mid-August, during a review prompted by a July breach at AI platform Hugging Face. It notified Services Australia and the Victorian Department of Health on September 10, the NSW bureau on September 18 and the institute on September 24.
OpenAI said the institute’s case “did not meet our disclosure thresholds” because the access seemed consistent with public access. “We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” it said.
Albanese said the incidents showed the risks of the technology, alongside its benefits for productivity, health and research.
“There are risks, and we’ve seen those risks exposed not just in what occurred in Australia, but the revelation that that has occurred in the United States and other countries as well,” he said on Tuesday.
OpenAI’s chief strategy officer, Jason Kwon, will fly in from the US to appear before parliament’s Joint Select Committee on Artificial Intelligence in Sydney on October 6, as this masthead reported on Monday. Anthropic will appear before the same committee that day.
Neither company will appear at Thursday’s hearing of a separate Senate inquiry into AI and data centres.
“We know we have a lot of work ahead of us to rebuild trust,” OpenAI said.
Cut through the noise of federal politics with news, views and expert analysis. Subscribers can sign up to our weekly Inside Politics newsletter.
David Swan is the technology editor for The Age and The Sydney Morning Herald. He was previously technology editor for The Australian newspaper.Connect via X or email.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.