The Australian government has initiated a review into a hacking incident in which tech giant OpenAI’s artificial intelligence (AI) model secured unintended access to private health files, marking one of the first publicly reported examples of an AI-led hack impacting a government website.
As per the BBC, which first reported the breach, OpenAI’s model gained access to files from several government websites and services in June after it was tasked with health statistics research. This includes data from Australia’s public health scheme, Medicare, which is not available to the public.
Discover B2B Marketing That Performs
Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.
While the hacking incident occurred in June, OpenAI claims it was not aware of the event until August. After discovering the breach, OpenAI informed Australian authorities of the incident on 10 September via an email to the Services Australia general email inbox.
In a statement to Pharmaceutical Technology, OpenAI noted an “extensive review of misaligned model activity” found no evidence of patient records being accessed, though accessed information included aggregate health statistics and internal file names.
“We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities,” the spokesperson added.
Currently, OpenAI holds partnerships with a broad range of life sciences companies, including pharma giants like Novo and Eli Lilly, as well as Thermo Fisher Scientific’s clinical trials business.
Governance an essential consideration amid AI’s rise to life sciences fame
While there is no evidence to suggest that the OpenAI hacking incident prompted a leak in patient data, the incident adds to growing concerns around unregulated AI’s potential impact on cybersecurity and patient health. This comes as the technology becomes increasingly embedded within the healthcare and life science sectors.
Huntress’ EMEA vCISO and cybersecurity advisor, Muhammad Yahya Patel, also raises concerns around the time it took OpenAI to identify the issue.
“If OpenAI’s own monitoring didn’t catch this for two months, how many other environments are currently being accessed by AI agents in ways their developers haven’t intended and don’t yet know about?” Patel questions.
“The industry was worried about AI agents taking unexpected actions in evaluation environments. The difference here is that this wasn’t a controlled test; This was a production government system,” he adds.
With the uptake of AI showing no signs of slowing down, Patel points to the ever-growing importance of airtight governance around AI – particularly in high-risk, regulated contexts such as R&D, where patient safety and privacy may be at risk.
Meanwhile, Graeme Stewart, head of public sector at Check Point, highlights the need for suitable guardrails and least-privilege access, as well as clear accountability and suitable visibility of AI agents to keep the technology’s activity in check.
“Boards should stop asking only whether they are compliant and ask the question that really matters: if an autonomous agent got into our systems tomorrow, could we keep operating and keep people safe? Nobody should wait for the next incident to find out,” Stewart concluded.
