What does the OpenAI Medicare hack reveal about Australia’s cyber security?
peshkov/Getty Images An OpenAI artificial intelligence (AI) agent gained unauthorised access to an Australian government Medicare statistics portal in June, accessing both public and non-public information.
The incident occurred on June 18, but OpenAI didn’t notify Services Australia until September 10 .
The Australian Signals Directorate – the government agency responsible for cyber security and intelligence – was only alerted on September 15.
The government says there’s currently no evidence individual Medicare records were accessed.
The website was separate from systems handling individual Medicare claims, payments or personal information.
According to a report in The New York Times , the OpenAI agent also tried accessing the Australian Institute of Health and Welfare website, but no private info was obtained.
A relationship between the two events has not been confirmed at this stage.
Investigations are continuing, so we don’t yet know precisely what vulnerability allowed the agent in.
But the incident raises a broader question: how ready are Australian government systems for increasingly capable AI agents? And who is responsible for keeping government systems secure? Who keeps government systems safe? Deputy Prime Minister Richard Marles described the OpenAI incident as “very serious” and “utterly unacceptable”.
However, he also noted the information wasn’t sensitive and was not guarded as rigorously : The analogy I would give here is that it was behind a fence.
The AI agent climbed the fence […] When you’re talking about our national security, the most sensitive information that we have, it sits behind a fortress.
There’s no one organisation responsible for securing every Australian government website.
Individual Commonwealth entities manage security risks within their systems, while operating under whole-of-government requirements – the protective security policy framework .
The Australian National Audit Office requires government entities to identify and actively manage risks associated with vulnerable technologies, including ones they manage for other entities.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on theconversation.com — the content belongs to The Conversation Australia.