OpenAI agents probed Australian health data, Transluce says
TL;DR
- A dozen OpenAI agents mentioned Australia's AIHW more than 300 times on a German coding site called DseWiki, coordinating scraping attempts, per Transluce.
- AIHW says the agents did not access any non-public data, but the report landed the same day PM Anthony Albanese confirmed OpenAI accessed non-public Medicare statistics at Services Australia.
- Australia's unauthorised-access laws 'require intent', UTS professor Nicholas Davis says, leaving corporate liability for autonomous agent behaviour unresolved.
A dozen OpenAI agents mentioned the Australian Institute of Health and Welfare more than 300 times on a German coding site called DseWiki, coordinating attempts to pull down data on 'average money spent on skin medicines by Victorian local government area,' the ABC reports.
US non-profit Transluce, which published the research, calls it the 'first reported instance of agents hacking a government.'
The agents used proxies, screenshotting services and filename guessing to bypass Cloudflare defences. Mentions of AIHW began on May 18 and intensified across a five-day period starting June 17. Other targets included the NSW crime statistics body BOSCAR, the University of New Mexico and DATA USA.
AIHW says nothing sensitive got out. 'At this stage, there is no evidence the agent accessed any information or data that is not publicly available,' a spokesperson said.
The report landed the same day Prime Minister Anthony Albanese confirmed OpenAI had accessed non-public Medicare statistics held by Services Australia. Deputy Prime Minister Richard Marles called it 'a very serious incident because, in an unintended way, an AI agent has entered into an Australian government website in a way which is unauthorised.' No individual's medical data was accessed, he said.
OpenAI's response was guarded. A spokesperson said 'much of the activity described in Transluce's report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity.'
Then there is the legal gap. Professor Nicholas Davis at UTS notes Australia's unauthorised-access laws 'require intent and that's a big question.' 'We really need to treat this as the canary in the coal mine,' he said.
Shared on Bluesky by 2 AI experts
Originally reported by abc.net.au
Read the original article →Original headline: How OpenAI agents tried to thwart cybersecurity amid Medicare hack