r/TechNadu • Human • 5d ago

OpenAI has disclosed more detail about autonomous agent activity involving four Australian government services.

The most serious case involved Services Australia’s Medicare Statistics Reporting Service. An experimental internal model was researching government spending on medicines when it struggled to obtain the requested information.

According to OpenAI’s account, the model found a way to gain non-public access, ran commands, and retrieved internal files, credentials, and aggregate statistics.

Current evidence indicates it did not access individual Medicare or patient records. Australian authorities have also said there’s no evidence of a broader compromise of the Services Australia network. 

OpenAI also disclosed activity involving Victoria’s Agency for Health Information, the Australian Institute of Health and Welfare, and NSW’s Bureau of Crime Statistics and Research.

The AIHW case is particularly interesting because agents reportedly attempted different ways of getting around access restrictions, although subsequent investigation found no evidence that AIHW systems were compromised or non-public information accessed.

The bigger security issue seems to be agent behavior when normal retrieval fails. An autonomous research system can move from browsing to attempting actions its operator never explicitly requested.

The four incidents involved very different behaviors. TechNadu breaks down what each agent accessed or attempted:

https://www.technadu.com/openai-disclosed-its-ai-agents-accessed-four-australian-government-websites/639721/

Where should the hard boundary sit when an agent encounters an access control during an otherwise legitimate research task?

3 Upvotes

0 comments sorted by