Katy Gallagher, speaking to the media in Sydney earlier

Australia Launches Urgent Review after OpenAI Program Hacks Government Health Portal

One thing that has surprised experts is not just the breach by an autonomous AI program - but the fact that OpenAI only told the Australian government three months later, via an email to general address.

The breach happened on 18 June. OpenAI said it became aware of a potential breach during a broader review sometime in August.

On 10 September, it sent an email to the public inbox of Services Australia, the general services hub of the federal government.

On 15 September, Services Australia reported the notification to the Australian Cyber Security Centre. A few days later, the Minister for the Public Service, Katy Gallagher, was notified.

Asked by reporters how it took five days for Services Australia to notify the cybersecurity centre, Gallagher acknowledged that the inbox could be more actively monitored – it is currently "looked at once a day", Gallagher said earlier.

"It gets sometimes quite a number of notifications, sometimes many of them are hoaxes," she said.

Still, the notification shouldn't have been passed along in an email thread, Gallagher said.

"It should have been escalated through ASD's channels or through the senior levels of Services Australia."

Australia's Deputy PM Richard Marles used an analogy of the accessed data sitting behind a fence: "It was not sitting behind a particularly high fence. This AI agent scaled the fence."

Some early estimate analysis online from cyber experts suggests that the computer systems were very poorly protected and it wouldn’t have taken long for a skilled human hacker to find a way around the defences.

So this is not an example of strong defences being overpowered by a skilled agent swarm - the kind of thing we have been warned about and seen in other cases.

But of course, that is not the point.

This was just the latest case of AI agents ignoring laws around how to safely access online information and perhaps the most serious yet given the information was government controlled.

"There were blocks clearly which ?were coming back telling the AI agent 'no'. The AI agent found a way around those blocks - didn't accept no for ?an answer,” PM Albanese told ?reporters.

Murmurings are getting louder in the cyber security world that AI companies are not being taken to task effectively enough when their bots carry out illegal hacks.

And as far as recent examples go - OpenAI’s agents seem to be more happy than most to ignore existing rules to carry out their tasks.

(Source: BBC)