Independent Member for Kooyong, Dr Monique Ryan, says the OpenAI agent’s breach of a Medicare system is a wake-up call the Albanese Government cannot ignore.
The agent accessed Services Australia’s Medicare Statistics Reporting Service in June. OpenAI told the government nearly three months later, by email to a generic inbox.
Dr Ryan: “Australians trust Medicare with their most sensitive personal information. That trust must be protected.
“We don’t know how far this intrusion went. We didn’t detect it ourselves. We found out because a foreign tech company eventually bothered to send an email. Now we’re relying on that same company’s word about what happened. It’s not good enough.
“Australia has been far too passive about AI, its risks and regulation. We’re exposed, and we need to act now to protect Australians’ data and privacy.”
Last week, I joined my crossbench colleague, Kate Chaney MP, in calling for the AI Safety Institute’s funding to rise from about $8 million per year to $100 million a year. In Question Time on 17 September, the Prime Minister rebuffed that call despite the government having known about the OpenAI breach for a week.
Dr Ryan: “The AI Safety Institute is meant to be our frontline defence against AI risk, but it’s being run on a shoestring and has fewer staff members than a suburban supermarket.
“We must move much faster to regulate AI. The government hasn’t yet presented draft legislation for a National AI Safety Act, and its draft standards barely mention requiring AI companies to disclose breaches.
“If an Australian hacked Medicare, you’d hope they’d face jail. Until we get our act together, international AI companies face no accountability at all.”
Dr Ryan is calling on the Government to act before the end of this parliamentary year, by:
Releasing the timeline and findings of the Australian Signals Directorate’s investigation of this breach.
Immediately increasing funding of the AI Safety Institute.
Legislating mandatory requirements for AI companies to report breaches, with penalties for failing to do so.
Making AI companies legally liable for harm caused by their agents.
Bringing forward AI safety legislation for high-risk settings.