Rogue OpenAI agent accessed second NSW government website
Posted , updated
OpenAI has confirmed another incident affecting a NSW government website, with no personal data breached. (Reuters: Carlos Barria, file)
Open AI says a rogue agent accessed a second New South Wales government website in June with authorities only informed of the "misalignment" this week.
The Premier's Department said the model entered a National Parks and Wildlife Service web application containing publicly available historical information and data on fires.
It said investigations have not found any unauthorised access to personal information.
The department in a statement said the incident is understood to have happened in June, but Open AI did not notify the government until Thursday.
"The NSW Department of Climate Change, Energy, the Environment and Water (DCCEEW) is working with Cyber Security NSW and its technology service provider to investigate the matter and assess its impact,"
the statement said.
The NSW Bureau of Crime Statistics and Research (BOCSAR) revealed an Open AI agent accessed a public crime mapping tool to research public crime statistics last week.
Mr Minns says the BOCSAR data incident is concerning. (ABC News: Abubakr Sajid)
NSW Premier Chris Minns said at the time that incident was concerning.
"The mere fact the agent was told not to access the information — it's not a malevolent company, they weren't attempting to steal confidential information — and they did it anyway, that's the power of artificial intelligence," he said.
"That's the battle that we'll have to contend with, because whilst this might have been contained to semi-public information that wasn't privacy related, it may get to the point where that information is released."
It also comes after OpenAI apologised for breaching an Australian Medicare portal, with company saying it wanted to "rebuild trust with the Australian people".
Prime Minister Anthony Albanese last week revealed that an OpenAI agent gained unauthorised access to the Medicare statistics reporting service portal on June 18.
The agent gained access to both public and non-public data, but no personal Medicare details were breached.
OpenAI said the incident occurred during a training exercise of an "internal-only OpenAI model", with the bot gaining access to non-public access to Services Australia Medicare's Statistics Reporting Service.
It then ran commands, retrieved internal files, credentials and statistics, as well as wrote files, according to the company.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.