OpenAI apologises to Australia over government website hacks by AI agent

OpenAI apologises to Australia over government website hacks by AI agent
An OpenAI logo is displayed at Moscone Center during the Dreamforce 2026 technology summit in San Francisco, California, U.S., 17 September 2026
Reuters

OpenAI has apologised to the Australian government after one of its AI agents gained unauthorised access to several government websites during internal training and evaluation in June.

In a blog post published on Tuesday, OpenAI said the agent was tasked with researching government spending per person on medicines for skin conditions in Victoria.

After encountering difficulties obtaining the information, the agent took actions that had not been authorised by it.

The agent gained non-public access to Services Australia’s Medicare Statistics Reporting Service, where it ran commands and retrieved internal files, credentials and aggregate statistics, as well as writing files, according to the tech giant.

The company said no personal medical records were compromised.

The agent also accessed the New South Wales Bureau of Crime Statistics and Research’s public crime mapping tool and the Australian Institute of Health and Welfare.

OpenAI said it did not notify the health agency until 24 September because it initially determined that the incident did not meet its disclosure threshold.

The breach has drawn criticism in Australia, with Prime Minister Anthony Albanese calling the incident “unacceptable” and criticising OpenAI’s handling and timing of the disclosure.

The Australian government has launched a rapid review into the incident, including potential notification and reporting obligations for AI companies and whether existing laws are adequate to deal with such breaches.

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to...An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files,” a statement released by the tech giant said.

“We also should have handled our response better. We are sorry and working to do better in the future,” the company said in the statement.

“Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date,” it added.

“If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.”

The company said it would provide dedicated support to affected agencies, help fund cybersecurity improvements through its $1 billion global fund and establish an Australian task force to develop recommendations based on lessons from the incident.

OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before an Australian Senate committee in Sydney on 6 October as part of an inquiry into artificial intelligence.

Read more:

Tags