Menu Menu
[gtranslate]

AI agents hacked Australia’s national healthcare database

Revealed during the United Nations General Assembly, this hack exposes a critical failure in current safety standards, sparking concerns over the future of AI.

In these past few years, conversations around AI seem to linger around a never-ending crossroads, with the recent shocking breach of Australian government data by OpenAI agents.

That said, I couldn’t tell you which is more concerning: the time it took the company to detect and report the breach, or the future implications, especially with AI’s rapid growth and its lack of regulations.

To start with, this infiltration tracks back to 18th June, when agents from OpenAI’s autonomous AI program breached and accessed data from Australia’s health insurance program, Medicare. However, it was not until the following month that OpenAI became aware of the situation.

All in all, it took OpenAI a grand total of three months to inform the Australian government, on September 10th via a generic email to the public inbox of Services Australia, that was checked just once a day.

Because this inbox was rarely monitored, Services Australia took 5 days to report to the nation’s Cyber Security Center. Only then was Prime Minister Anthony Albanese notified of the hack just before he departed to New York for the United Nations General Assembly (UNGA). It was there that he revealed the shocking breach to the world.

So, what do we know about the hack? Well, while conducting research on public health spending, these agents bypassed security blocks and accessed public and private files within Medicare’s statistics reporting portal. On top of this, they even wrote files directly into the database’s internal server.

While no personal medical records or broader digital infrastructure were compromised, it was reported that the agents also tried to breach three other systems.

Though this is the world’s first case of autonomous AI breaching government systems, recent times have seen similar breaches in other cases. A good example is the Hugging Face hack, also carried out by OpenAI’s autonomous agents that escaped their sandbox and launched a self-directed attack on the platform. 41 servers on the platforms ended up being compromised before the breach could be contained.

Similar cases have also happened with Anthropic’s Claude models that hacked into the infrastructure of three different companies, due to poor operational oversight.

The scariest part? In all these breaches, the companies responsible for the autonomous agents took a while to discover that their creations were going rogue. This is exactly why earlier this month, a bunch of Big AI CEOs came together and backed a proposal to slow down the development of AI.

While the proposal was published by Dario Amodei himself, signatories include Sam Altman, Elon Musk, and Demis Hassabis.

Albanese said from the UNGA that after a ‘very frank discussion’ with Altman, OpenAI would be suffering legal consequences for the delayed disclosure, and rightfully so.

With AI taking center stage at the UNGA, the revelation of the Medicare breach pushed a joint appeal titled ‘A Call for Control of Frontier AI Models’, co-signed by 22 nations including Canada, Spain, Germany, and Australia.

The appeal detailed initiatives to push AI companies to develop better safety protocols, strengthen governmental regulations, and called for an UN-level institution to be created to oversee AI development and capabilities.

Unsurprisingly, the US and China chose not to sign the appeal given their hopes of achieving AI supremacy. In fact, during the UNGA, Trump repetitively made it a point to downplay the dangers of AI and called out the efforts to safeguard its usage as a ‘globalist scheme’.

AI CEOs did not follow suit though. Instead, they issued stark warnings to world leaders at the UN Security Council Briefing that humanity is on the verge of risking control of the future to AI.

Our current reality is such that AI development only continues to outpace the regulations that follow. This results not just in outdated policies, but also a grim unpreparedness for the next hack or attack that’s only going to be harder to detect.

So instead of sitting around and waiting for such a situation to happen, surely the best the world can do is heed the warnings of AI CEOs, and implement the measures proposed by the appeal before it’s too late.

Enjoyed this? Click here for more Gen Z focused tech stories.

Accessibility