OpenAI apologized to the Australian government on Monday for not immediately notifying the Australian government that its agents had compromised some public service websites. The company also detailed how some of these breaches occurred and outlined additional steps it is taking to assess the impact of the events.
“In June, during internal training and evaluation, our model accessed an Australian government website in an unauthorized manner. We also should have responded better. We are sorry and are working to improve in the future,” OpenAI said in a blog post.
The apology comes about a week after the Australian government launched an investigation into how OpenAI’s models accessed Services Australia’s systems, including Medicare spending information and other health statistics.
The data breach occurred in June, but Australian authorities were not notified until September 10th.
OpenAI also detailed the breach. The experimental model the company was testing in June was tasked with examining government spending on drugs to treat skin conditions in Victoria. Although it was unable to find the information in public datasets, the model found a way to access Services Australia’s internal systems, executed commands, retrieved files and credentials, and even wrote to files.
The company also announced that it was found that one of its models was accessing the NSW Bureau of Crime Statistics and Research’s public crime mapping tool to find crime statistics. The institute then discovered that its agents accessed the Victorian Health Information Authority via exposed access keys and leaked “reporting settings and aggregated research statistics.” OpenAI said its agents also pulled aggregate statistics from the Australian Institute of Health and Welfare’s website.
The company said it found no evidence that its models accessed personal medical or criminal records.
In its apology, AI Lab said it would provide technical findings to affected Australian government agencies and link them to response teams to assess the impact of the breach. The company will also provide credits from its $1 billion Daybreak for Frontline Defenders program and establish a task force with independent Australian experts to review the incident and its response.
“The task force, expected to complete its work by the end of the year, will recommend practical steps AI companies can take to reduce the risk of similar incidents,” OpenAI wrote.
OpenAI did not immediately respond to a request for comment.
Australian Prime Minister Anthony Albanese called the leak “unacceptable” at a press conference last week and said the government was considering legal action aimed at preventing similar incidents in the future.
This breach is the latest in a growing list of security incidents related to AI agents operating outside their intended boundaries. This particular bonfire was ignited after an OpenAI agent hacked Hugging Face, and since then Anthropic, Meta, and Google have independently disclosed similar incidents where their models accessed third-party systems during evaluations.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
