Australian Prime Minister Anthony Albanese this morning revealed to the public that an AI agent run by OpenAI – maker of ChatGPT – accessed Medicare documents that were “not for public consumption” back in June this year.
Speaking from New York this morning, where he’s holed up ahead of an address to the UN Security Council later today (ironically), Albo broke the news.
We’re waiting on the transcript for the full quotes but according to reports, Albanese said that an OpenAI agent breached Medicare records about three months ago. Albanese said he’s upset it took OpenAI this long to report it, and this reporter tends to agree.
“Medicare records” can mean a lot of things. In this instance, no personal data was stolen as a result of the hack. Instead, Albanese said the agent breached the “Medicare Statistics Reporting Portal” which ServiceAustralia manages.
These AI agents are meant to be sandboxed while they’re being tested so they don’t go and run amok on the open internet. And given the capability of these agents to read code, find ancient vulnerabilities and exploit them has caught the cybersecurity industry with its proverbial pants down in recent months. So much so that they’ve been described as hacking “super weapons” in previous commentary that we’ve reported.
And this isn’t an isolated incident. ChatGPT-maker OpenAI has been in some hot water recently after its AI “agents” were caught hacking big businesses as part of training exercises.
These training exercises as they’re called puts different versions of existing and emerging AI models to work to see how they respond, work together and solve problems.
The first big high-profile instance came when a swarm of OpenAI’s models breached a company known as HuggingFace which was later acquired by NVIDIA. The agents apparently weren’t looking for anything malicious and didn’t steal anything. Instead they were reportedly looking to find out how they could make it look like they passed a test set by OpenAI engineers.
This latest instance of OpenAI “hacking” likely won’t be the last you hear about, certainly not involving Australian interests.
I keep using “hacking” in quotes because I can’t imagine that OpenAI as a business would ever take a swarm of its AI super-agent swarms and point it at government agencies around the world. I’ve reported on big tech for almost two decades and I don’t have any faith in big tech to regulate itself like I once did, but this one is a little nuanced.
AI agents like ChatGPT, Claude, Perplexity, whatever, all work explicitly on the user’s behalf. The problem is that they have no compunction, politeness or real understanding of what’s “illegal” and what isn’t. They’re not going to give you advice on how to commit insider trading or hide a body, but if you ask them to complete a task, some can go to any lengths to satisfy a user’s ask.
The first “hack” of an Australian system by an AI agent was when a man asked his OpenClaw agent to book him a class at a gym. Upon the agent realising there were no more spots, it didn’t simply and politely report back “computer says no”, instead it found an exploit in the way that the gym’s booking system worked to jump him to the front of the queue. No data was stolen, but the “hack” was likely the result of a user asking for a task to be completed and the agent working against existing systems to satisfy a user’s demand.
Albo reckons he’s spoken to tech supervillain and OpenAI CEO Sam Altman in New York this morning to address his concerns. However, I’d bet my bottom dollar that this isn’t the last time we’ll hear about autonomous breaches of big systems like Medicare.