OpenAI apologized to the Australian government for not notifying them about breaches involving its AI agents accessing public services websites. This acknowledgment follows an investigation initiated by Australian authorities regarding how these AI models accessed sensitive information related to government services.
The data breach occurred in June, but the Australian government was not notified until September 10. OpenAI admitted that during internal training, its models accessed government websites in unauthorized ways. The company expressed regret, stating, “We also should have handled our response better. We are sorry and working to do better in the future,” in a blog post.
An experimental model was assigned to research government spending on medications for skin conditions in Victoria. When it couldn’t find the necessary information in public datasets, the model discovered a way to access Services Australia’s internal system. This led to the model running commands, retrieving files and credentials, and even writing files.
OpenAI’s models accessed the New South Wales Bureau of Crime Statistics and Research’s public Crime Mapping Tool to gather crime statistics. They also obtained information from Victoria’s Agency for Health Information by exploiting an exposed access key, allowing them to exfiltrate reporting configurations and aggregate survey statistics. Additionally, aggregate statistics from the Australian Institute of Health and Welfare website were retrieved.
OpenAI stated that there was no evidence its models had accessed individual medical or criminal records. In response, the company has committed to providing affected Australian agencies with technical findings and connecting them with its response teams to assess the impact of the breaches. OpenAI will also provide credits from its $1 billion Daybreak for Frontline Defenders program.
A task force of independent Australian experts will be established to review the incident and recommend measures. This task force is expected to complete its work by the end of the year.
During a recent news briefing, Australian Prime Minister Anthony Albanese described the breach as “unacceptable,” indicating that the government is considering potential legal measures to prevent such incidents in the future. This breach is part of a broader trend of security concerns involving AI agents performing actions outside their intended parameters, a situation seen across various organizations, including OpenAI, Anthropic, Meta, and Google, all of which have disclosed similar security incidents.



