Medicare wasn't hacked.
Last week it was reported that "a rogue OpenAI agent" had "hacked" Medicare, Australia's universal health insurance scheme. What did the agent do, exactly? It "infiltrated" a statistics portal members of the public had been scraping for over a year (the script was on Github).
In other words, it was an absolute nothing burger. But it does get to a bigger issue with AI: I'm not sure most people know what hacking really is, and that leaves them exposed to an even graver threat: political opportunism.
For decades now, hacking has been less about code breaking and more about social engineering, or phishing. That is, identifying people who have access to something, be it a company's contact list, a bank account, or root access to a server, and then using psychological tricks to convince them into providing access to the hacker.
To prevent modern hacking, that means you need to harden your people more than your software, the latter of which is usually pretty robust because IT geeks (and now AI) have been working on 'hardening' this stuff for decades. But Fred in accounts? Yeah, nah. That means asking people to use a password manager rather than the same password1 for every website. Use two factor authentication or passkeys. Don't answer cold calls or emails without first verifying the authenticity of the person (or AI) on the other end. Things like that.
AI doesn't change that calculus. It might increase the quantity of attempts and improve the sophistication of Nigerian Prince emails, but ultimately a modern "hack" usually requires somebody to leave a door open by mistake. In the case of Medicare, the failure was the bureaucrats who uploaded files onto a publicly reachable legacy portal, and the OpenAI staff who ran an agent evaluation loose enough that their models "took actions we did not intend" (secure your sandboxes!).
But there is a bigger risk when "hacks" like this become public, and it's political: elites seize the opportunity enabled by the media's obsession with using "hack" in headlines and people's general misunderstanding of the concept to rush through regulation that causes real harm, as opposed to the imaginary harms being caused by AI.
Enter Anthony Albanese. Australia's paternalistic Prime Minister, who is clearly not content with his world-leading suppression of speech, jumped on the "hack":
"Albanese said he spoke to [OpenAI CEO Sam] Altman and raised 'Australia's extreme concern about this incident' as well as his 'disappointment' that the company had taken months to reveal the breach and 'the nature of the way' it did so.
...
'No personal information is believed to have been accessed at this stage, but investigations are ongoing,' Albanese said.'Nonetheless this situation is obviously unacceptable,' he said."
When OpenAI discovered the breach, it waited a month (not months) before sending an email to Services Australia's public disclosures address. Only then did the Australian government find out, and then it took nearly a fortnight for Albo to make the "hack" public.
What worries me is the strength of Albo's statement. Deputy PM Richard Marles said "the information that it obtained, was minor in its nature, in as much as that information we’ve now made public anyway – it wasn't anyone’s personal data". But you wouldn't know that from Albo's response, which exaggerated the timeline, talked up the severity, and criticised OpenAI for using his own government's public disclosure address.
Is he softening the public up for social media ban-type regulation? I'm not aware of any bill in the works, yet. But there's already a taskforce run out of the Prime Minister's department, promises of "legal consequences", a Greens senator asking for Sam Altman and Dario Amodei to appear before her Senate inquiry, and calls for a moratorium on AI data centre approvals. And this is all before the Office of AI, established 15 July, has got its regulatory mojo together.
Politicians love to use a crisis, and their favourite time to strike is when the tide of fear and uncertainty is strong. To paraphrase Ben Franklin, I suspect we're going to see plenty of regulation trading "liberty" for "safety" in the AI space, and Australians will be worse off because of it.
About the author
Justin Pyvis
Independent economist and casual techie based in Perth, Western Australia.More →
Related
Subscribe to the newsletter.
Get new essays delivered to your inbox. No spam. Unsubscribe anytime.