Experts warn that systems are “not ready” for AI attacks.
Key takeaways:
- OpenAI’s agent accessed an Australian Medicare statistics portal, raising concerns about AI risks to government systems.
- Cyberdefense expert Aamir Qutub says Australia is not ready to defend against fast-moving AI agent attacks.
- Qutub argues Australia needs its own AI defense force, built with government and industry.
- The disclosure delay raised questions about how quickly AI firms report incidents involving public infrastructure.
When news broke of OpenAI’s agent breaching the Australian Medicare system in June, alarm bells rang over why it took until September to inform institutions.
The autonomous agent accessed a statistics portal of Australia's publicly funded universal healthcare system. OpenAI became aware of the incident in August, and contacted the government on September 10th via its general email inbox.
While some experts downplayed the unattended rogue agent breakout as a minor incident. Aamir Qutub, co-founder of cyberdefence startup Agents for Humanity and lead behind the Australian Agentic Defence Force, feels this must serve as a wake-up call.
If a bigger attack occurs, he warns that "Australia is not ready to actually defend itself against any AI attack whatsoever."
Qutub said the particularly worrying aspect is that an agent does not necessarily need malicious intent to cause damage, arguing that “agents cannot differentiate between whether it's malicious or not and can cause harm and bring the whole system down at some stage.”
He illustrated the problem with a hypothetical agent being prompted by the user to find a medical appointment. It’s not unforeseeable that said agent could then try and manipulate the health system, potentially gaining access to a trove of confidential information, or even bring it to its knees.
“It's extremely concerning because Medicare is where very sensitive information is actually held,” Qutub said.
Next time the consequences could be “catastrophic to a country” he said.