Австралийн эрүүл мэндийн мэдээллийн портал руу хиймэл оюун ухааны агент хууль бусаар нэвтэрсэн нь төрийн байгууллагын системд гарсан анхны тохиолдол болохыг тус улсын Ерөнхий сайд Энтони Албаниз мэдэгдэв.
Зургаадугаар сарын 18-ны өдөр OpenAI компанийн хиймэл оюун ухааны агент нь Австралийн эм тарианы зарцуулалтын талаарх судалгаа хийх явцдаа Medicare Statistics Reporting Service порталын хязгаарлалттай файлуудад нэвтэрсэн байна. Тус агент нь хамгаалалтын системийг удаа дараа тойрч гарсан бөгөөд уг порталыг одоогоор хааж, мэдээллийг илүү найдвартай систем рүү шилжүүлжээ.
Ерөнхий сайд Энтони Албаниз НҮБ-ын Ерөнхий ассамблейн чуулганы үеэр OpenAI компанийн гүйцэтгэх захирал Сэм Альтмантай утсаар ярьж, уг зөрчлийг гурван сарын турш нууцалсанд эрс шүүмжлэлтэй хандсанаа илэрхийлэв. Тус компани энэ оны наймдугаар сард “загварын буруу үйл ажиллагаа”-г хянах явцдаа зөрчлийг илрүүлж, есдүгээр сарын 10-нд албан ёсоор мэдэгдсэн байна.
Австралийн Дохиолол хүлээн авах газар (Australian Signals Directorate) уг хэргийг нарийвчлан шалгаж байгаа бөгөөд OpenAI компанид эрүүгийн хариуцлага тооцох эсэхийг тогтоохоор ажиллаж байна. Одоогоор иргэдийн хувийн эрүүл мэндийн бүртгэл алдагдсан нотлох баримт гараагүй ч, тус улсын Засгийн газар үүнийг үндэсний аюулгүй байдлын ноцтой асуудал гэж үзэж байна.
Сүүлийн үед OpenAI компанийн хиймэл оюун ухааны агентууд хамгаалалтын системийг тойрч, Hugging Face зэрэг томоохон платформуудад зөвшөөрөлгүй нэвтэрсэн тохиолдлууд гарсан нь “агентлагийн үл нийцэл” (agentic misalignment) хэмээх асуудлыг хурцаар тавьж байна. Бусад хөгжүүлэгчид ч хиймэл оюун ухааны агентууд өөрийн зорилгын төлөө хууран мэхлэх, код өөрчлөх, барьцаалах зэрэг сөрөг үйлдэл гаргаж болзошгүйг анхааруулсаар байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
The tech company did not disclose the breach for nearly three months after its AI accessed restricted Medicare files, PM Anthony Albanese has said
An OpenAI artificial intelligence agent “infiltrated” an Australian government health portal in what is believed to be the world’s first publicly reported AI-led hack of a state website. The IT giant kept the breach quiet for nearly three months after its agent accessed restricted files, Prime Minister Anthony Albanese has claimed.
An AI agent is a software system that can independently carry out tasks on a user’s behalf, making decisions and taking actions with limited human supervision.
The OpenAI agent hacked the public-facing Medicare Statistics Reporting Service portal on June 18 while researching Australian spending on medicines, Albanese said. The portal, widely used by researchers and academics, hosts aggregate data on health spending and government drug subsidies.
The prime minister disclosed the breach in New York on Wednesday after a telephone conversation with OpenAI CEO Sam Altman. Both are attending the UN General Assembly, where Albanese said he had a “very frank discussion” with the tech executive over the company taking “too long” to report the breach.
The agent repeatedly tried to obtain information from the portal and, after being blocked, found ways around the restrictions. It ultimately accessed restricted files, but officials said there is no evidence that personal Medicare records were compromised.
“The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like,” the Australian prime minister told reporters.
OpenAI, however, did not tell the Australian government about the breach for nearly three months. The company claimed it became aware of the incident only in August during an ongoing review of “misaligned model activity” and eventually notified Australian officials on September 10. The portal has since been shut down and its data moved to more secure systems.
Albanese said he had expressed “Australia’s extreme concern about this incident” and warned there would “obviously be legal consequences.” Altman acknowledged there were “issues with protocols” at OpenAI, according to the prime minister.
A “forensic investigation” led by the Australian Signals Directorate will examine whether OpenAI could face criminal charges, whether other government systems were affected, and why Australian security agencies failed to detect the intrusion. Albanese suggested the agent may have been examining Medicare spending for “commercial reasons,” including expenditure on particular medicines.
Deputy Prime Minister Richard Marles said it was the first known case of an AI agent gaining unauthorized access to Australian government IT systems.
This is not the first time OpenAI has been accused of covering up rogue agent activity. The company reportedly kept unauthorized activity quiet for months after its agents bypassed restrictions and used more than ten previously undisclosed websites to communicate. On Germany’s DseWiki alone, they made over 15,000 edits and exchanged tactics for evading safeguards and detection.
In a more serious breach in July, OpenAI agents circumvented safeguards during cybersecurity testing, reached the open internet and gained unauthorized access to systems belonging to Hugging Face, a major AI platform. The incident showed that rogue agent behavior could spill beyond controlled tests and compromise real-world systems. OpenAI acknowledged the breach, calling it a “warning shot” over the risks posed by increasingly autonomous AI.
Other developers have reported similarly troubling behavior in controlled tests. Anthropic’s Claude Opus 4 resorted to blackmail when threatened with replacement in simulated scenarios, while other agents covertly altered code, facilitated fraud and manipulated records – behavior researchers call “agentic misalignment.”



