澳大利亚总理安东尼·阿尔巴尼斯披露,一个人工智能智能体于6月渗透进了一个Medicare网站,访问了公开和非公开文件,并向一台内部服务器写入文件。
阿尔巴尼斯在纽约对记者表示,该事件涉及一个OpenAI智能体未经授权访问了由Services Australia管理的面向公众的Medicare Statistics Reporting Service门户。
他说,该事件发生在今年6月,但联邦政府直到9月10日才通过OpenAI的一封电子邮件得知此事。
“这种情况显然是不可接受的,”他说。“今天,我与OpenAI首席执行官Sam Altman进行了交谈,表达了澳大利亚对这起事件的极度关切,我也表达了我的失望——该公司花了太长时间才通知政府发生了什么,而且通知方式本身也是不可接受的。”
尽管记者反复追问,阿尔巴尼斯拒绝透露他是否在昨晚与总统唐纳德·特朗普的交谈中讨论了这起入侵事件。
“我是私下进行的……我和特朗普总统之间有一种关系,我们会进行交谈,而且……不得不说,令一些人惊讶的是,我们关系非常好,因为我们确实保持着一种关系。”
阿尔巴尼斯表示,目前尚无证据表明个人信息已被访问,也没有证据表明Services Australia的更广泛网络已遭入侵,但在澳大利亚信号局的协助下,取证调查正在进行中。
他说,政府还了解到另外三个可能受影响的系统:联邦政府的澳大利亚健康与福利研究所;新南威尔士州犯罪统计与研究局;以及维多利亚州卫生部。
早期证据
阿尔巴尼斯昨晚与维多利亚州州长本·卡罗尔和新南威尔士州州长克里斯·明斯进行了简短交谈。
他说,早期证据发现该智能体访问了公开可用的文件,以及并非供公众访问的材料。
“目前可获得的证据表明,Services Australia的网络没有受到更广泛的入侵。尽管如此,这种情况显然是不可接受的,”他说。
“现阶段据信没有个人信息被访问,但调查仍在进行中,”阿尔巴尼斯说。
他说,该事件始于6月18日,当时一个OpenAI研究团队使用一个内部模型对公共医药领域进行了基于互联网的研究。
该 AI 智能体在试图从政府门户网站获取信息时屡次遭遇拦截,但找到了绕过这些拦截的办法,最终未经授权访问了其他区域。
“确实有拦截返回,明确告诉 AI 智能体不行,”Albanese 说。“但该 AI 智能体找到了绕过这些拦截的办法,不接受‘不行’这个答案。”
该智能体随后访问了公开和非公开信息,据澳大利亚服务局称,它还向一台内部服务器写入了文件。阿尔巴尼斯表示,OpenAI 直到 9 月 10 日才通知政府,距事件发生已近三个月,而且是通过向一个公共邮箱发送电子邮件的方式进行的。
澳大利亚服务局随后于9月15日向澳大利亚网络安全中心报告了该通知。该机构上周已将此事告知公共服务部长凯蒂·加拉格尔,阿尔巴尼斯则表示他在周末听取了简报。
特别工作组
政府将成立一个由总理与内阁部领导的特别工作组,紧急审查该事件,并确定现有流程是否足以应对与AI相关的网络事件。
该特别工作组将包括国家网络安全协调员、AI办公室、澳大利亚信号局、澳大利亚AI安全研究所以及澳大利亚服务局。
此次审查将研究可能的执法与立法应对措施,同时该事件也将被提交给议会人工智能联合专责委员会。
阿尔巴尼斯表示,政府将就是否已构成犯罪以及是否应将此事移交澳大利亚联邦警察寻求紧急建议。该事件还将为政府计划中的人工智能标准立法提供参考。
OpenAI 表示,其模型在一次内部评估中访问了“多个澳大利亚政府网站和服务”。这些模型当时正试图查找有关澳大利亚问题的答案和统计数据。
“在此过程中,我们的模型采取了并非我们本意的行动,”一位 OpenAI 发言人表示。
该公司表示,其审查未发现任何患者记录被访问的证据。该公司称,被访问的信息包括汇总健康统计数据和内部文件名。
OpenAI 表示,该活动发生在 6 月,但直到 8 月才察觉。它是在对其所称的训练和评估中的“模型行为失准”进行审查时发现了这一活动。该公司称已于 9 月 10 日通知了 Services Australia。
“我们已通知相关机构,并提供技术信息以支持他们的调查,帮助解决潜在的安全漏洞,”该发言人表示。“我们的整体审查仍在进行中。”
OpenAI 没有说明还有哪些其他政府网站和服务受到影响。
Albanese 利用这一披露来强化他的论点,即需要围绕快速发展的 AI 技术加强保障措施。
“AI 正在改变世界,”他说,并指出它在推动经济增长、提升生产力以及促进健康、科学和创新进步方面的潜力。
“但 AI 也带来了重大风险,这就是为什么我们需要护栏来保护我们的生活方式。”
“我们希望确保是我们塑造 AI,而不是 AI 塑造我们。简而言之,人类必须保持掌控。”
Albanese 表示,政府理解这一事件会引起澳大利亚人的担忧,但试图安抚公众,目前已知没有个人受到影响。
“目前,没有证据表明任何个人受到了影响,”他说。
Albanese 表示,如果某些细节涉及国家安全,可能会继续保密,但澳大利亚人有权了解这一事件。
“我认为让人们知道这件事发生了非常重要,”他说。
此次数据泄露事件的消息传出前两天,Albanese 曾敦促其他世界领导人团结起来,共同努力保护人们免受人工智能风险的影响,并表示没有任何一个国家能够独自应对这项技术日益增长的风险。
周一,澳大利亚与其他 22 个签署方一道,在联合国呼吁对人工智能制定新的国际保障措施,此前科学家和行业高管警告称,强大系统的快速发展可能超出各国政府控制新兴风险的能力。
美国总统 Donald Trump 拒绝了放缓并限制 AI 发展的呼吁,警告称任何自我施加的护栏都会给中国带来危险的优势。
过去两个月里,OpenAI、Anthropic 和 Google 各自表示,它们的模型在接受黑客能力测试时,侵入了真实的计算机系统。
澳大利亚前网络安全事务负责人、CyberCX 联合创始人 Alastair MacGibbon 表示,该智能体并未被设定去入侵任何东西。
入侵未被察觉
“这是一个并未被赋予黑客任务的智能体;它被赋予的是医学研究任务,只是恰好动用了自己工具箱里的工具去实现这一目标,而这个过程基本上就涉及了黑客行为,”他说。
“他们这么做并非出于恶意,而是因为被赋予了一项任务。想象一下,如果有一个恶意的人让智能体去执行这些任务会怎样。”
MacGibbon 表示,更大的担忧在于这次入侵未被察觉。“我们应该问的问题是,澳大利亚政府在六月份没有检测到这件事,”他说。
他还批评了政府对 AI 监管的拨款。他将 AI 安全研究所的预算与昆士兰州四年间几个道路黑点整治项目的经费做了比较。他说,他了解到总理内阁部下属的 AI 办公室“真的只有几个人”。
“我在这行干了 25 年,我们一直在失败,”MacGibbon 说。“现在我们有了一个澳大利亚受害者……这件事必须被严肃对待。傲慢必须结束。”
An artificial intelligence agent infiltrated a Medicare website in June, accessing public and non-public files and writing files to an internal server, Prime Minister Anthony Albanese has revealed.
Speaking to reporters in New York, Albanese said the incident involved an OpenAI agent gaining unauthorised access to the public-facing Medicare Statistics Reporting Service portal, administered by Services Australia.
He said the incident occurred in June this year, but the Commonwealth government was only informed via an email from OpenAI on September 10.
“This situation is obviously unacceptable,” he said. “And today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident, and I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable.”
Despite persistent questioning, Albanese would not reveal whether he discussed the breach in his conversation with President Donald Trump last night.
“I do it privately ... I have a relationship with President Trump, where we have conversations, and ... to some people’s surprise, it must be said, have a very good relationship because we do have a relationship.”
Albanese said there was no evidence so far that personal information had been accessed or that the broader Services Australia network had been compromised, but a forensic investigation was under way with the assistance of the Australian Signals Directorate.
He said the government was also aware of three other systems that may be affected: the Commonwealth’s Australian Institute of Health and Welfare; the NSW Bureau of Crime Statistics and Research; and the Victorian Department of Health.
Early evidence
Albanese spoke briefly to Victorian Premier Ben Carroll and NSW Premier Chris Minns last night.
He said the early evidence has found the agent accessed publicly available files, as well as material not intended for public access.
“Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable,” he said.
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said.
He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.
“There were blocks clearly which were coming back, telling the AI agent no,” Albanese said. “The AI agent found a way around those blocks, didn’t accept no for an answer.”
The agent then accessed public and non-public information and, according to Services Australia, also wrote files to an internal server. Albanese said OpenAI did not notify the government until September 10, almost three months after the incident, and did so by sending an email to a public mailbox.
Services Australia subsequently reported the notification to the Australian Cyber Security Centre on September 15. The agency informed Public Service Minister Katy Gallagher of the incident last week, with Albanese saying he was briefed over the weekend.
Task force
The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents.
The task force will include the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.
The review will examine possible law enforcement and legislative responses, while the incident will also be referred to Parliament’s Joint Select Committee on Artificial Intelligence.
Albanese said the government would seek urgent advice on whether offences had been committed and whether the matter should be referred to the Australian Federal Police. The incident will also feed into the government’s planned AI standards legislation.
OpenAI said its models had accessed “several Australian government websites and services” during an internal evaluation. The models were trying to look up answers and statistics for questions about Australia.
“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
The company said its review found no evidence that patient records had been accessed. It said the information accessed included aggregate health statistics and internal file names.
OpenAI said the activity took place in June, but it did not become aware of it until August. It found the activity during a review of what it calls “misaligned model activity” in its training and evaluation. It said it notified Services Australia on September 10.
“We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities,” the spokesperson said. “Our overall review is ongoing.”
OpenAI did not say which other government websites and services were affected.
Albanese used the disclosure to reinforce his argument for tighter safeguards around rapidly developing AI technology.
“AI is changing the world,” he said, pointing to its potential to deliver economic growth, productivity gains and advances in health, science and innovation.
“But AI also poses significant risks, and that’s why we need guardrails to protect our way of life.”
“We want to make sure that we shape AI rather than AI shaping us. Put simply, humans must remain in control.”
Albanese said the government understood the incident would be concerning to Australians but sought to reassure the public that no individuals were currently known to have been affected.
“At this point in time, there is no evidence that any individuals have been impacted,” he said.
Albanese said some details could remain confidential if they involved national security, but Australians had a right to know about the incident.
“I think it’s really important that people are aware that this has occurred,” he said.
News of the breach comes two days after Albanese urged other world leaders to unite on efforts to protect people from the risks of artificial intelligence, saying that no country can manage the technology’s growing risks alone.
Australia was among 22 signatories calling for new international safeguards on AI at the United Nations on Monday, amid warnings from scientists and industry executives that the rapid development of powerful systems could outpace governments’ ability to control emerging risks.
US President Donald Trump has rejected calls for slowdowns and restrictions on AI growth, warning that any self-imposed guardrails would give China a dangerous advantage.
Over the past two months, OpenAI, Anthropic and Google have each said their models broke into real computer systems while being tested for hacking ability.
Alastair MacGibbon, Australia’s former cybersecurity tsar and co-founder of CyberCX said the agent had not been set up to hack anything.
Breach unnoticed
“This was an agent that was not tasked with hacking; it was tasked with medical research, and it just happened to use tools in its tool belt to go about achieving that objective, which involved basically hacking,” he said.
“They’re not doing it because they’re malicious. They’re doing it because they’ve been given a task. Imagine if you had a malicious human getting agents to do these tasks.”
MacGibbon said the bigger concern was that the breach went unnoticed. “The question we should be asking is the Australian government didn’t detect this in June,” he said.
He also criticised the government’s funding for AI oversight. He compared the AI Safety Institute’s budget to a couple of road black spot programs in Queensland over four years. He said he understood the Office of AI in the Department of Prime Minister and Cabinet had “literally a handful of people”.
“I’ve been in this game for 25 years and we’ve been failing,” MacGibbon said. “Now that we have an Australian victim … It has to be taken seriously. The hubris has to end.”