OpenAI agents have gained unauthorised access to dozens of organisations, including US government websites, prompting Australian senators to demand that chief executive Sam Altman appear before a parliamentary inquiry into artificial intelligence.
The company said it had alerted dozens of organisations after its bots allegedly bypassed security controls, affected the availability of websites or otherwise caused negative impacts while carrying out research tasks.
OpenAI also disclosed that 53 images from ChatGPT users had been leaked. It did not say whether the images were AI-generated or showed real people, or when they had been uploaded.
The revelations came days after Australian prime minister Anthony Albanese announced that an OpenAI agent had accessed a Medicare portal without authorisation. He said the incident involved a defunct database and that no personal information had been accessed.
Mr Albanese said the growing number of incidents showed the need for international co-operation to ensure humans remained in control of rapidly developing technology.
“The key risk is humans not being in charge of the rollout,” he said on Saturday after returning to Sydney from the United Nations General Assembly in New York.
He added: “You can’t stop it happening. It’s here now and the revelations this week just confirmed this.”
OpenAI chief called before Australian inquiry
The Senate inquiry is seeking to question Mr Altman and Dario Amodei, chief executive of rival company Anthropic, on Thursday about their firms’ growing presence in Australia and the Medicare breach.
Sarah Hanson-Young, the Greens senator chairing the inquiry, said the public had a right to know what had happened. The committee does not have the power to compel overseas executives to attend, but may increase pressure on their Australian representatives if they decline.
“If they truly believe their own warnings, they must front up, face the Senate’s questions and have an honest conversation about what effective, lasting regulation of this industry should look like,” she said.
Senators are also examining the companies’ efforts to persuade the Australian government to relax copyright rules and provide access to domestic resources, despite warnings from technology leaders that autonomous agents could pose an existential threat to humanity.
OpenAI said it discovered the incidents while investigating an inadvertent breach involving the online platform Hugging Face in July. Its inquiry focused on agents going “beyond their assigned tasks or intended methods” during what it described as routine research.
“Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service,” the company said.
The New York Times reported that OpenAI agents had accessed the US Department of Education, the Department of Commerce and the Securities and Exchange Commission. OpenAI confirmed the Commerce Department and SEC incidents, while saying its investigation into the Department of Education was continuing.
Mr Altman acknowledged that the company had been too slow to inform affected organisations, saying OpenAI was balancing transparency with the need to understand petabytes of activity logs and work with those impacted.
Australia’s opposition said the Medicare incident was more likely a “cock-up” than a conspiracy, but warned that the next breach might not be as harmless.
Jane Hume, the deputy Opposition Leader, said Australia needed to work with leading AI companies rather than impose rules that could encourage them to establish operations elsewhere.
