Australian senators are seeking to question OpenAI chief executive Sam Altman after the company disclosed that its autonomous agents had accessed United States government websites and leaked 53 images from ChatGPT users.
The revelations came days after Prime Minister Anthony Albanese announced that an OpenAI agent had gained unauthorised access to a Medicare portal in June. He said the widening security concerns showed the need for international action to keep humans in control of rapidly developing technology.
Australia’s parliamentary inquiry into artificial intelligence has summoned Altman and Dario Amodei, chief executive of Anthropic, to appear on Thursday over the companies’ expanding operations in Australia and the Medicare incident.
Sarah Hanson-Young, the committee chair and a Greens senator, said the public was entitled to know what had happened. “This can’t all be done behind closed doors – the public has a right to know what went on here,” she said.
The inquiry cannot compel foreign executives to attend, although senators could increase pressure on the companies’ Australian representatives if they refuse to appear.
OpenAI agents under scrutiny
In a lengthy statement, OpenAI said it had informed dozens of organisations that its agents may have bypassed security controls, affected the availability of websites or otherwise caused harm while carrying out routine research tasks.
The company said it discovered the incidents during an investigation into the inadvertent hacking of the online platform Hugging Face in July. It said the agents had gone “beyond their assigned tasks or intended methods”.
OpenAI said most of the cases identified so far were of lower severity, with limited or no evidence of a significant impact on third-party services. It confirmed incidents involving the US Department of Commerce and the Securities and Exchange Commission, while an investigation into an alleged breach of the Department of Education remained under way.
The company also disclosed that agents had leaked 53 images from ChatGPT users. It did not say whether the images were AI-generated or showed identifiable people, or when they had been posted.
Altman acknowledged that OpenAI had been too slow to inform affected organisations. “We have not been as fast as we would have liked, but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organisations,” he said in a social media post.
Albanese said Australia had acted in its national interest by making the Medicare breach public. Although the agent accessed a defunct database and did not obtain personal information, the incident was one of the first publicly disclosed cases of an AI agent breaking into a government website.
“You can’t stop it happening. It’s here now and the revelations this week just confirmed this,” the prime minister said after returning from the United Nations General Assembly in New York.
He added: “The key risk is humans not being in charge of the rollout.” Albanese said international co-operation would be essential as the technology developed.
The Opposition has argued that Australia should obtain the most advanced US AI models to strengthen its cyber security defences. Jane Hume, the deputy Opposition Leader, said the Medicare incident was more likely to have been a “cock-up” than a conspiracy, but warned that a future breach might not be as limited.
“This is the wake-up call that we need,” she told 2GB. “We’ve got to make sure that we get those AI companies working with Australia, not imposing ridiculous rules upon them that they simply will not abide by, which means that they go and set up elsewhere.”
