OpenAI has apologised for an AI agent’s unauthorised access to Australian government systems and pledged funding and technical support to strengthen cybersecurity following the incident.
The company said the breach occurred in June during internal training and evaluation of an experimental AI model, but was not disclosed publicly until September.
OpenAI said the model accessed the Services Australia Medicare Statistics Reporting Service, where it ran commands, retrieved internal files and credentials, accessed aggregate statistics and wrote files.
The company said its investigation had found no evidence that medical records were accessed. It also said activity involving three other Australian government agencies did not result in access to sensitive records.
“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI said in a blog post.
“We also should have handled our response better. We are sorry and working to do better in the future.”
The incident prompted criticism from Australian Prime Minister Anthony Albanese, who previously described the unauthorised access as unacceptable and questioned why the government was not notified sooner.
OpenAI said it would provide dedicated support to affected government agencies and contribute resources to strengthen cybersecurity for government and industry through its $1 billion global fund.
The company also plans to establish an Australian task force to develop recommendations based on lessons from the incident.
OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before an Australian Senate committee in Sydney on October 6 as scrutiny of the incident continues.
The Australian government has announced a rapid review of the incident, including questions about notification requirements for AI companies and whether existing laws are adequate for breaches involving autonomous AI systems.
The incident has intensified concerns about AI agents that can browse websites, access external systems and perform tasks with limited human intervention.
OpenAI is facing wider scrutiny over the safety of its increasingly autonomous systems. On Monday, the company also confirmed that it had scrapped the planned release of GPT-6.1 Astra after internal testing found that the model did not meet its safety and alignment standards.
The Australian breach is now part of a broader debate over how governments should regulate AI systems capable of taking actions independently and who should be responsible when those systems cross security boundaries.















