AI bots broke into ‘dozens’ of government sites, OpenAI confirms
OpenAI has confirmed its autonomous (artificial intelligence) AI bots bypassed security controls on the websites of “dozens” of organisations, including high-profile government and university systems.
The revelation comes after Prime Minister Anthony Albanese confirmed that an AI bot operated by the tech giant gained unauthorised access to an Australian Medicare statistics website in June.
OpenAI chief executive Sam Altman refused to answer whether he should apologise to the Australian government and why it took months to report the unexpected bypass. AP Photo/Carolyn Kaster
In a statement posted on Saturday (local time), OpenAI said it would not publicly name all affected entities, citing privacy requests from those impacted.
"Our goal is to give each organisation the facts and defer to them on if and when to make the incident public," the company stated.
However, according to The New York Times, targeted platforms in the US included the Department of Education, the Department of Commerce, and the Securities and Exchange Commission (SEC).
OpenAI explained that some of its AI agents used specialised software development tools to interact with “authoritative sources of public information”.
The company emphasised that the data accessed was already publicly accessible.
AI agents are software programs trained to operate autonomously, carrying out complex tasks following pre-programmed instructions.
The company noted that not all incidents are being categorised as severe security breaches, describing many of the occurrences as “agent spam”.
This is instances where AI bots unexpectedly attempt to submit or scrape data online without being prompted to do so.
“Some organisations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning,” OpenAI said.
“Others may identify a design issue or security weakness they want to address.”
The unauthorised activity was discovered during an ongoing investigation into a separate security incident involving the open-source platform Hugging Face in July.
Prime Minister Anthony Albanese announced the AI hack, involving the Medicare Statistics Reporting Service portal from New York. Nine
The statement comes days after Prime Minister Anthony Albanese confirmed that an OpenAI bot had accessed a Medicare public statistics page earlier this year.
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” he said while in New York for the United Nations General Assembly.
“Evidence currently available is [that] there is no broader compromise to the Services Australia network.”
Albanese revealed he spoke directly with OpenAI Chief Executive Sam Altman to express his frustration over the incident and the company’s delayed communication.
He said that he was disappointed that it took OpenAI “way too long” to inform the government about the breach.
Share a tip-off, video or photo with us
Related Stories
AI News
Adtech vet Brian O'Kelley's startup is pivoting to AI agents and rebranding with a new name
20 minutes ago
AI News
China and the US agree to set up a new AI safety channel, and to keep talking on trade, military
50 minutes ago
AI News
Trump-Xi takeaways: White House touts progress on artificial intelligence, Iran and exports
50 minutes ago
AI News
China, US to open AI ‘communication channel’ after summit, White House says
50 minutes ago
AI News
U.S. should err on the side of innovation in AI regulation, U.S. Rep. Arrington says
1 hour ago
AI News
Japan's Sumitomo Life to deploy AI for tailor
1 hour ago
AI News
OpenAI Agents Accessed US Government Websites Without Authorization
1 hour ago
AI News
Artificial Intelligence Stocks To Watch Today
2 hours ago