Blog

PM alleges ‘unauthorised access’ of Medicare portal

Australian Prime Minister Anthony Albanese has alleged an AI agent, developed by OpenAI, gained ‘unauthorised access’ to a statistics reporting service portal for Medicare, the country’s public health insurance scheme earlier this year.

Mr Albanese made the allegation in New York on Wednesday, local time.

“This incident occurred in June this year and involved an Open AI agent gaining unauthorised access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia,” Mr Albanese told reporters.

He went on to note, “The AI agent accessed both public and non-public files. A forensic investigation, aided by the Australian Signals Directorate, is now under way to ascertain more information, including what other government systems were affected.

“The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics, such as spending.

“No personal information is believed to have been accessed at this stage but investigations are ongoing.

“Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable.

“Today, I spoke with the CEO of Open AI, Sam Altman, to express Australia’s extreme concern about this incident.

“And I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” Mr Albanese said.

OpenAI response

In a statement provided to Pulse+IT, an OpenAI spokesperson said: “As we’ve shared publicly, OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems.”

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.

“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names. We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities. Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”

The spokesperson went on to note, “During that time, we were validating and investigating the facts and what information had been accessed. The recorded activity occurred in June, however we weren’t aware of this until August during an ongoing review of OpenAI misaligned model activity. We notified Services Australia on 10 September.”

Services Australia has been approached for comment.