Australian senators are demanding the heads of multiple tech companies appear at an inquiry after an OpenAI agent breached systems in Australia and around the world.
It comes as Prime Minister Anthony Albanese insisted the company had questions to answer following the breach, where an AI bot operated by OpenAI gained unauthorised access to an Australian Medicare statistics website in June.
Prime Minister Anthony Albanese insisted OpenAI has questions to answer after Thursday’s breach. Today
OpenAI has confirmed its autonomous (artificial intelligence) AI bots bypassed security controls on the websites of “dozens” of organisations, including high-profile government and university systems.
In a statement posted on Saturday (local time), OpenAI said it would not publicly name all affected entities, citing privacy requests from those impacted.
“Our goal is to give each organisation the facts and defer to them on if and when to make the incident public,” the company stated.
OpenAI chief executive Sam Altman refused to answer whether he should apologise to the Australian government and why it took months to report the unexpected bypass. AP Photo/Carolyn Kaster
However, according to The New York Times, targeted platforms in the US included the Department of Education, the Department of Commerce, and the Securities and Exchange Commission (SEC).
Speaking to reporters on Saturday, Albanese said it was natural that questions would be raised after several breaches of the same nature.
“It’s up to OpenAI to state why it is then that [there are] now multiple cases where this has occurred,” he said.
“What this does is confirm … [is] that there needs to be [an] appropriate national response, as well as an international response, to make sure that humans stay in charge.”
A Greens-led Senate inquiry, which is looking at AI and the rollout of massive data centres across the country, has now called for Sam Altman and Anthropic CEO Dario Amodei to appear in front of the inquiry this week to hold the companies account for the breaches and to explain their growth in Australia.
“This can’t all be done behind closed doors – the public has a right to know what went on here,” committee chair and Greens senator Sarah Hanson-Young said.
“If they truly believe their own warnings, they must front up, face the Senate’s questions and have an honest conversation about what effective, lasting regulation of this industry should look like.”
In a statement regarding the latest breach, OpenAI explained that some of its AI agents used specialised software development tools to interact with “authoritative sources of public information”.
Prime Minister Anthony Albanese announced the AI hack, involving the Medicare Statistics Reporting Service portal from New York. Nine
The company emphasised that the data accessed was already publicly accessible.
AI agents are software programs trained to operate autonomously, carrying out complex tasks following pre-programmed instructions.
The company noted that not all incidents are being categorised as severe security breaches, describing many of the occurrences as “agent spam”.
This is instances where AI bots unexpectedly attempt to submit or scrape data online without being prompted to do so.
“Some organisations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning,” OpenAI said.
“Others may identify a design issue or security weakness they want to address.”
The unauthorised activity was discovered during an ongoing investigation into a separate security incident involving the open-source platform Hugging Face in July.
The statement comes days after Prime Minister Anthony Albanese confirmed that an OpenAI bot had accessed a Medicare public statistics page earlier this year.
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” he said while in New York for the United Nations General Assembly.
“Evidence currently available is [that] there is no broader compromise to the Services Australia network.”
Albanese revealed he spoke directly with OpenAI Chief Executive Sam Altman to express his frustration over the incident and the company’s delayed communication.
He said that he was disappointed that it took OpenAI “way too long” to inform the government about the breach.