The escalation of cyber breaches in Australian government departments will be investigated after it took five days for bureaucrats to pass on Open AI’s disclosure that its AI agent hacked Medicare data.
OpenAI, the developer of ChatGPT, has publicly admitted its AI agents acted independently to gain unauthorised access to Services Australia on June 18.
OpenAI claimed they identified the breach in August but it took until September 10, nearly three months after the hack for the firm to alert the department via email.
However, their email to Services Australia’s dedicated cyber incident reporting line took the agency five days to escalate to the Australian Signals Directorate.
The notification timeline and pathway to Australia’s peak intelligence agency and lack of domestic alerts to the “mis-aligned” AI activity has raised questions across the political spectrum.
Opposition leader Angus Taylor said there were “critical questions” around the process and insisted Australia needed to strengthen its cyber defences.
“We need to know more about what’s happened here and the timelines involved. Timelines as to when the Government was informed of this,” Mr Taylor said.
Greens Senator David Shoebridge said there appeared to be “multiple failures” between the US tech company and the Government.
Labor Senior Senator Katy Gallagher defended Services Australia staff, insisting it checked the inbox daily and picked up the email on September 11.
She said Services Australia had to first “analyse” and “verify” the email’s claims against their internal logs and data to ensure the report was “legitimate”.
Their email address was called public.disclosure@servicesaustralia.gov.au which is a dedicated contact to report cyber security incidents to the department.
Senator Gallagher also noted that within the five days it took public servants to escalate the matter, on September 15, “there was a weekend in there as well”.
Prime Minister Anthony Albanese first revealed the breach to the public on Thursday while in New York for the UN General Assembly.
He told reporters at a press conference that he’d called OpenAI boss Sam Altman to express his “disappointment” with both the incident and also how Australia was notified.
Months after the breach and just days before OpenAI formally reported it to Australia, Defence Minister Richard Marles and Mr Albanese’s AI lead Andrew Charlton had travelled to the US and met with Mr Altman.
There had been no public acknowledgement that the group discussed a potential breach.
OpenAI’s vice president of global policy Ann O’Leary had also been in Canberra on September 14 to speak at the Australian Strategic Policy Institute’s summit about AI.
While also speaking at the same event, Australian Signals Directorate director-general Abigail Bradshaw had insisted the nation needs an AI “early warning system” for emerging threats.
She also used her speech to urge Australian companies to ramp up defensive capabilities.
Senator Gallagher said she was personally told about the breach on Thursday, September 17 before several ministers, including Mr Marles and Home Affairs Minister Tony Burke, received a briefing across the weekend.
It came days before Mr Albalnese’s point guard on AI Dr Charlton was told.
“I was first told about it over the weekend,” he confirmed in an interview with ABC Radio on Thursday.
It was only on Tuesday this week, September 22, that OpenAI and Services Australian had their first technical exchange covering logs and data.
Senator Gallagher vowed there would be “subsequent meetings” between the company and government.
After Mr Albanese’s announcement of the breach and pledge to establish a taskforce to look into the incident, the government released the Terms of Reference of the rapid review.
It included examining the escalation pathways, establishing clear rules and systems when breaches occur, forcing companies to report and corporate when breaches are discovered, and evaluating whether the current laws and enforcement mechanisms are strong enough.
It will also seek to harden the Government’s systems against AI-specific vulnerabilities.
“These terms of reference are to guide a Department of the Prime Minister and Cabinet-led rapid-review of an artificial intelligence related cyber-incident affecting Australian Government systems,” it states.
“The objective of the review is to determine whether existing legislative, governance, and information-sharing arrangements are fit-for purpose to prepare for, and respond to, a cyber incident involving AI.
“The review will also inform how to build and maintain resilient systems in the AI era.”
Senator Gallagher told a press conference she had requested the government’s recent Budget investment into cyber uplift of Services Australia’s essential infrastructure be accelerated, as well as all other legacy public-facing websites.
The revelations came just days before the national audit office published a report on how the Department of Health, Disability and Ageing is effectively managing AI technology.
It claimed the department needed to be more “proactive” in using AI to identify incorrect or fraudulent Medicare claims after 3779 were detected in 2024-25 - costing $5.2 million but an AI model only helped find eight of them.
However, the report also found issues around AI cyber security risks and recommended the department strengthen its defences and ensure its “cyber security policies reflect AI risks”.
“Consideration of legal and cyber security risks is not yet sufficient,” it stated.
The Prime Minister has also confirmed the Government has sought urgent advice on whether Australian Federal Police should investigate the breach as a criminal matter.
Mr Albanese had delivered a keynote address at the University of Sydney on July 15, when he pledged that Labor would create world-first AI standards for how tech companies operate, comply with copyright concerns, and power data centres.
Get the latest news from thewest.com.au in your inbox.
Sign up for our emails