AIartificial intellegencedata securityFeaturedHealth carehealth data

Did Skynet hack Australian Medicare, or are AI titans just looking to scare regulators?

On June 18th, Open AI robot-agents were researching health data posted on Australian public facing reports when they apparently broke into an area they were not authorized to be.

What the agent reached was Services Australia’s Medicare Statistics Reporting Service—a public-facing research portal of aggregate spending numbers, not the claims system that holds patient files. Deputy Prime Minister Richard Marles called the impact “relatively minor.”

OpenAI says it found aggregate statistics and internal file names, and no patient records. On three other government sites the same agent touched, Marles said it behaved like a member of the public. Nobody has published how the bypass worked. That is a lot of UN-stage theater for a statistics page.

Washington’s own skeptics have already named the real defendant. Treasury Secretary Scott Bessent, after the July Hugging Face break-in, told CNBC the episode was “the responsibility of the OpenAI management, not a bunch of agents.” He told the House Financial Services Committee humans are liable for what they build, and that labs should not get a liability shield. President Trump this week told the U.N. the extinction panic is a “hoax.”

AI companies have experienced the biggest transfer of wealth into a new market sector than anything in history. Since ChatGPT’s late-2022 launch, almost $33 trillion has been added to S&P 500 market value, the vast majority from companies whose futures are tied to AI. So the President’s skepticism when the AI titans ask for regulation may be rooted in their desire to put a fence around the $33 trillion to prevent future competition. But healthy caution is still in order.

An agent given a lookup task did not stop at “no.” It wrote files onto a government server. OpenAI noticed Australia only in an August review, then emailed a public mailbox on September 10. If a person had done this, we would call it unauthorized access and ask why the door was unlocked. Bessent’s line still holds: lock the portals, time the disclosure, and put the invoice on the managers—not on a ghost in the machine.

Patients should be concerned about the potential for a data breach that could leak their personal health information. If you have cancer or a family predisposition to certain diseases, insurers, private companies, potential employers or competitors may be willing to pay big money for that information.

Those who remember paper medical charts were always at risk to snoopy nurses or staff at your doctor’s office. But breaches today risk instant access by anyone in the world attached to the internet. Minnesota’s Optum experienced a data breach leaked over 190 million people’s records. Medical records. Patient data. Open AI only accessed reporting on aggregate data. No patient information. So how should patients read this?

Real malicious human hackers are still a bigger threat to patient data than AI robots. Keep an eye on both. But whenever billionaires ask to be regulated, better to keep the sharper sharp eye on the humans.

Source link

Related Posts

1 of 429