该 OpenAI 智能体未经授权访问了公开和非公开文件,这可能是已知的首例 AI 智能体入侵政府网站的事件。
2026 年 9 月 23 日,在美国纽约,澳大利亚总理安东尼·阿尔巴尼斯在联合国大会期间的一场新闻发布会上发言,披露 OpenAI 开发的一个 AI 智能体于 6 月侵入了澳大利亚一个政府网站。(图片来源:Reuters/AAP/Mick Tsika)
在 FAST 上阅读本文摘要。
通过全新的
卡片界面获取精简新闻。不妨一试。
点击此处返回 FAST
点按此处返回 FAST
FAST
悉尼:澳大利亚周三(9 月 23 日)表示,一个 OpenAI 智能体于 6 月突破了政府健康数据门户,未经授权访问了文件,这可能是已知的首例 AI 智能体入侵政府网站的事件。
这起入侵事件是 AI 智能体在美国境外访问外部系统的最高调事件之一,此前全球已发生数起由失控 AI 智能体引发的入侵事件,令各国政府和企业感到警惕。
澳大利亚总理安东尼·阿尔巴尼斯表示,该 OpenAI 智能体未经授权访问了一个政府机构的医疗统计门户网站,该机构负责非敏感健康数据与统计,包括公共医疗支出。
“目前可获得的证据表明,该……网络并未遭到更大范围的入侵。尽管如此,这一情况显然是不可接受的,”阿尔巴尼斯在纽约的一场媒体简报会上表示,他正在那里出席联合国大会。
CNA 游戏
猜词
逐行破解单词
热词
用给定的字母组成单词
迷你数独
小巧谜题,烧脑挑战
迷你填字
小网格,大挑战
找词游戏
尽可能多地找出单词
显示更多
收起
阿尔巴尼斯表示,调查仍在继续,澳大利亚已就“这一事件向 OpenAI CEO Sam Altman 表达了极度关切”,并补充说,他对该公司延迟通知政府深感失望。
“直到 9 月 10 日才出现任何通知,”阿尔巴尼斯说,并补充说,调查还将审查为什么政府系统一开始未能检测到这次入侵。
他还警告说,另外三个政府网站“可能受到”OpenAI 智能体活动的影响。
“问题是,当它试图收集数据时,是否进入了这些其他网站?所以我们不能确认这种情况发生过,”他说。
这一事件发生之前,OpenAI 和 Anthropic 本月分别向一项议会调查提交了材料,敦促澳大利亚重新考虑一项禁止它们使用该国创意内容来训练模型的禁令。
OpenAI 称 AI 模型在测试中失控,引发该初创公司“前所未有的”入侵事件
OpenAI 的软件在针对 Hugging Face 之前还瞄准了另一个网站
“AI 模型试图查找答案”
这次入侵发生在 OpenAI 开展训练演练、为 AI 模型的表现打分之时。
政府服务部长凯蒂·加拉格尔对记者表示,它要求该模型在网上搜集数据,以展示澳大利亚政府在药品上花费了多少资金。
这家总部位于旧金山的公司直到本月才通知澳大利亚政府,当时它向一个通用的政府邮箱发送了一封电子邮件。
“那个邮箱地址每天只查看一次,”加拉格尔说。
“我们有专人去查看。它有时会收到大量通知;其中很多往往是恶作剧。”
国防部长理查德·马尔斯表示,该 AI 模型“翻越了围栏”。
“它提出了一个问题,信息没有被提供,而它没有就此止步,而是翻越了围栏。”
OpenAI 表示,它在 8 月对其 AI 模型进行“广泛审查”时发现了这一违规行为。
“我们的审查没有发现患者记录被访问的证据。被访问的信息包括汇总健康统计数据和内部文件名,”该公司在一份声明中表示。
它补充说,它“识别出涉及多个澳大利亚政府网站和服务的活动,因为我们的模型试图查找答案……我们的模型采取了我们并未预期的行动”。
这起入侵事件是OpenAI近期披露的多起事件之一,这些事件均涉及该公司的AI智能体遭到黑客攻击或出现未经授权的活动,且都是在事发很久之后才被披露。
在某些情况下,这是因为相关活动直到很晚才被发现;而在另一些情况下,则是因为该公司最初选择不予披露。
根据OpenAI和独立调查人员公布的时间线,另一起备受瞩目的事件——7月中旬对开源AI代码库Hugging Face的入侵——在发生约一周后才被发现。
这助推了一场关于日益强大的AI模型所带来风险的全球性讨论。
竞争对手Anthropic、Google的Gemini以及Meta也披露了各自智能体访问外部系统的事件。
包括Altman在内的多位美国顶尖AI高管呼吁放缓AI发展步伐,理由包括失控的智能体可能发动毁灭性网络攻击等威胁。
研究人员利用Claude入侵了OpenAI的内部系统
CNA解读:为何AI领袖呼吁放缓——以及为何如此困难
来源:Agencies/co/rl
订阅我们的精选头条和发人深省的文章,直达你的收件箱
下载 CNA 应用
开启通知,随时获取突发新闻和我们的精选报道
获取 WhatsApp 提醒
加入我们的频道,在你常用的聊天应用上获取每日热门阅读
同样值得一读
内容加载中……
展开阅读完整报道
通过全新的
卡片界面获取精简新闻。快来试试吧。
点击此处返回 FAST
点按此处返回 FAST
FAST
The OpenAI agent gained unauthorised access to public and non-public files in what could be the first known instance of an AI agent hacking a government website.
Australia's Prime Minister Anthony Albanese speaks at a press conference during the United Nations General Assembly, revealing an AI agent developed by OpenAI infiltrated an Australian government website in June, in New York, US, on Sep 23, 2026. (Photo: Reuters/AAP/Mick Tsika)
Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST
SYDNEY: Australia said on Wednesday (Sep 23) an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.
The breach is one of the highest-profile incidents of AI agents accessing external systems outside the United States, coming on top of several recent breaches globally by rogue AI agents that have alarmed governments and companies.
Prime Minister Anthony Albanese said the OpenAI agent gained unauthorised access to the medical statistics portal of a government agency responsible for non-sensitive health data and statistics, including public medical spending.
"Evidence currently available is there is no broader compromise to the ... network. Nonetheless, this situation is obviously unacceptable," Albanese said during a media briefing in New York, where he is attending the UN General Assembly.
CNA Games
Guess Word
Crack the word, one row at a time
Buzzword
Create words using the given letters
Mini Sudoku
Tiny puzzle, mighty brain teaser
Mini Crossword
Small grid, big challenge
Word Search
Spot as many words as you can
Show More
Show Less
Investigations continue and Australia had voiced its "extreme concern about this incident" to OpenAI CEO Sam Altman, Albanese said, adding that he was deeply disappointed by the company's delay in notifying the government.
"It took until Sep 10 before there was any notification at all," Albanese said, adding that the investigation would also examine why government systems had failed to detect the breach in the first place.
He also warned that three other government websites "may be impacted" by the OpenAI agent's activity.
"The question is, when it was trying to harvest data, did it go into these other sites? So we're not confirming that that occurred," he said.
The incident comes after OpenAI and Anthropic, in separate submissions to a parliamentary inquiry this month, urged Australia to reconsider a ban preventing them from using the country's creative content to train their models.
OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup
OpenAI's software targeted another site before Hugging Face
"AI MODELS ATTEMPTED TO LOOK UP ANSWERS"
The breach occurred when OpenAI ran training exercises to rate the performance of AI models.
It asked the model to trawl the internet for data showing how much the Australian government spent on medicine, Government Services Minister Katy Gallagher told reporters.
The San Francisco-based company did not alert the Australian government until this month, when it sent an email to a generic government inbox.
"That email address is looked at once a day," Gallagher said.
"We have someone who goes and has a look through. It sometimes gets a number of notifications; sometimes many of them are hoaxes."
Defence Minister Richard Marles said the AI model had "scaled the fence".
"It asked a question, the information was not given and rather than leaving at that point, it scaled the fence."
OpenAI said it spotted the breach in August while carrying out an "extensive review" of its AI models.
"Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names," the company said in a statement.
It added that it "identified activity involving several Australian government websites and services as our models attempted to look up answers ... our models took actions we did not intend".
The breach is one of several recent incidents in which OpenAI has disclosed hacks or unauthorised activity involving its AI agents well after they occurred.
In some cases this was because the activity was only detected belatedly, and in others because the company initially elected not to disclose it.
A separate high-profile incident, a mid-July intrusion into open-source AI repository Hugging Face, was only detected about a week after it took place, according to timelines released by OpenAI and independent investigators.
This helped ignite a global conversation about the risks posed by increasingly powerful AI models.
Rivals Anthropic, Google's Gemini, and Meta have also disclosed incidents of their agents accessing external systems.
Some of America's top AI executives, including Altman, have called for a slowdown of AI development, citing, among other things, the threat of devastating cyberattacks by out-of-control agents.
Researchers used Claude to breach OpenAI's internal systems
CNA Explains: Why AI leaders are calling for a slowdown – and what makes it so difficult
Source: Agencies/co/rl
Get our pick of top stories and thought-provoking articles in your inbox
Get the CNA app
Stay updated with notifications for breaking news and our best stories
Get WhatsApp alerts
Join our channel for the top reads for the day on your preferred chat app
Also worth reading
Content is loading...
Expand to read the full story
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST