Global AI cybersecurity concerns face new twist following Australia Medicare portal breach

The U.N. Security Council heard from AI developers about the necessity of frontier model safeguards the same day Australia revealed an OpenAI agent breached government websites on its own volition.

Contributors:
Lexie White
Staff Writer
IAPP
During a press conference at the United Nations General Assembly, Australian Prime Minister Anthony Albanese announced an investigation into new revelations regarding an OpenAI agent's alleged breach of Service Australia's Medicare portal. The incident marks the first publicly disclosed instance of agentic AI accessing a government website without human instruction.
Albanese said the agent breached the Medicare Statistics Reporting Service 18 June while conducting research into health and medical statistics. However, the department was only informed of the incident via email 10 Sept.
"The AI agent accessed both public and non-public files," Albanese told reporters. "No personal information is believed to have been accessed at this stage, but investigations are ongoing. Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable."
While a broader probe into the incident by the Australian Signals Directorate is underway, Albanese shared initial facts and observatiuons.
OpenAI's agent allegedly accessed aggregate data from the Medicare Statistics Reporting Service and may have impacted the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research. Albanese said the agent encountered blocks by Australia's systems before attempting "alternative ways to obtain the info that it wanted," ultimately resulting in the unauthorized access.
In a private conversation with OpenAI CEO Sam Altman, Albanese indicated he expressed "extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred."
Following Albanese's disclosure of the incident, the Australian Cyber Security Centre released guidance warning organizations of the potential risks that AI agents could take unprompted actions. The ACSC urged organizations to implement authentication safeguards, continuously update their systems and bolster incident response plans to address AI-related security risks.
OpenAI spokesperson Drew Pusateri told the Guardian that an internal evaluation to identify statistics showed activity involving several Australian government websites.
"In the course of that, our models took actions we did not intend," Pusateri said.
Australia's Deputy Prime Minister Richard Marles said while the government believes the data breach's impact on systems is "relatively minor," an AI agent'S unauthorized access to government websites and systems is "completely unacceptable."
Concerns mounting
The incident comes as calls for frontier model safeguards are picking up steam among global policymakers and AI developers. Those discussions resurfaced during the U.N. Security Council's 23 Sept. meeting on AI and international security, where OpenAI, Anthropic and Hugging Face spoke on the rapid advancement of their AI systems and how it could negatively impact consumers while threatening critical infrastructure.
Hugging Face CEO Clem Delangue highlighted cybersecurity risks after witnessing impacts firsthand months ago when an OpenAI agent escaped its testing environment and breached Hugging Face's systems.
Delangue urged increased transparency across developers regarding security breaches and potential vulnerabilities, noting the company found similar incidents had previously occurred at other frontier AI labs.
OpenAI's Altman highlighted the need for all AI stakeholders to put competitive goals aside in favor of safety. Global governments have become divided on balancing innovation and safety due to the economic benefits of AI leadership.
"The industry must not accept too much technological risk just because the benefits are too great, and that they feel too important to slow down," Altman said. "Beating companies in a competitive race is not a reason to make rash decisions."
From a regulatory standpoint, Altman said each government "should decide how to incorporate standards into its own legal system,” but urged alignment "on what good evidence, good safeguards and good oversight look like on the global stage.”
Anthropic CEO Dario Amodei previously wrote a widely-supported essay calling for AI companies to slow innovation due to safety risks. He reiterated his views before the U.N. council, noting AI "could be a risk to humanity as a whole" if managed poorly while highlighting the importance of industry-wide and international safety standards to support risk mitigation.
"We will slow down as much as necessary in order to make sure that every successive AI technology that we release is actually safe," Amodei said. "But regardless of what we do, managing these risks is ultimately bigger than any one company, and it has an industry wide and global scale."
The AI cyber debate has more complexity than agents committing breaches, according to Delangue. Following the security incident involving OpenAI, Hugging Face was initially unable to use frontier models to strengthen its security system due to certain safeguards. The company instead chose to use open-source AI tools as part of its cyber defense plan.
"We were attacked by AI, but more importantly, we defended ourselves with AI," Delangue said. "The same systems that helped us during this attack are now helping us against cyberattacks we were already facing. (It) is also helping us fix the bugs and weaknesses in our systems before any attack."
Regulatory approaches
To establish cohesive AI safety guidelines, France called for a framework focused on independent model evaluations, transparency and clear liability standards for AI-related cybersecurity incidents.
"If we ignore the full range of repercussions that the development of AI will have on our societies, the anger of our fellow citizens will continue to grow and risk hindering the adoption of positive uses of these technologies," Minister for Europe and Foreign Affairs of France Jean-Noël Barrot said during the Security Council meeting. "Ultimately, the international community will need to establish a common framework to manage the risks associated with frontier AI models."
U.K. Secretary of State for Foreign, Commonwealth and Development Affairs Ed Miliband also called for increased testing of frontier AI models and government oversight into companies' development standards.
"We must start with safety," Miliband said. "This means working harder to ensure frontier AI models are rigorously tested and building a system of assurance around model development to allow us to establish trust that models are safe."
Despite many countries suggesting a comprehensive AI safety standards' agreement, White House Office of Science and Technology Policy Director Michael Kratsios held firm on the prior opposition U.S. President Donald Trump's administration has shown to establishing global rules, arguing individual countries should maintain authority over AI regulations.
"You cannot govern a technology you do not understand," Kratsios said. "This body, and others like it should focus on sharing best practices to build domestic capacity, not establishing a global regulatory scheme."
He noted the U.S. continues to work with companies to test frontier AI models and address potential vulnerabilities, but highlighted, "the frontier of intelligence is advancing rapidly" and concern and handling of that pace alone are "not a reason to pause its further development or to constrain it with new global governance structures."

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Lexie White
Staff Writer
IAPP
Tags:



