OpenAI apologizes after AI agents accessed Australian sites

The company said experimental models gained unauthorized access during June training, including to a Services Australia Medicare statistics system, and pledged an Australian task force.

Sam Altman seated across from Isaac Herzog during a meeting, with other participants in the room.

Photo: Amos Ben Gershom, CC BY-SA 3.0 (https://creativecommons.org/licenses/by-sa/3.0), via Wikimedia Commons (source)

OpenAI apologized for unauthorized access by its models to Australian government websites during internal training in June and said it should have handled its response better, according to a company post dated Sept. 28 and reported by TechCrunch on Tuesday.

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI wrote. It added that it “should have handled our response better” and is “sorry and working to do better in the future.”

The company said a mid-August review, started after a July incident involving Hugging Face, found activity affecting Services Australia, NSW's Bureau of Crime Statistics and Research, the Victoria's health department and the Australian Institute of Health and Welfare.

What OpenAI says happened

At Services Australia’s Medicare Statistics Reporting Service, OpenAI said an experimental internal model, not meant for public release, obtained non-public access, executed commands, pulled internal files and credentials plus aggregate statistics, and wrote files. The company said it found no evidence that individual patient or client records were accessed.

OpenAI said the model had been assigned a research task on Victoria's per-person spending for skin-condition medicines and, when it could not find the data in public sources, took actions the company had not authorized.

At the NSW bureau, OpenAI said a model queried a public crime-mapping tool and received application configuration, operational jobs, logs and site metadata, without reaching anyone's crime records. At Victoria's Agency for Health Information, it said agents used an exposed access key to pull reporting configuration and aggregate survey figures, not anyone's medical records. At the Australian Institute of Health and Welfare, it said agents pulled aggregate figures that looked publicly available, and failed when they tried to bypass access controls.

OpenAI said it alerted Services Australia and Victoria's health department on Sept. 10, the NSW bureau on Sept. 18 and the institute on Sept. 24. The company wrote that it "should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.".

Response and commitments

OpenAI said it has blocked live internet access in research environments in favor of cached content, expanded monitoring, and paused tool-use training and evaluation for its most capable models until more safeguards are ready.

In Australia, the company said it will give affected agencies technical findings and response-team support, provide credits from its $1 billion Daybreak fund for frontline defenders, and create a task force of independent Australian experts to recommend how firms notify governments and coordinate. The task force is expected to finish by the end of the year, OpenAI said.

Chief Strategy Officer Jason Kwon will testify before Australia's parliamentary AI committee in Sydney on Oct. 6, the company said.

What's next

TechCrunch reported that Australian Prime Minister Anthony Albanese last week called the breach “unacceptable” and said the government was weighing legal measures. OpenAI said it will keep sharing verified findings with affected agencies and publish updates on its review.

Sources

Motion Media News corrects errors promptly. To report one, email hello@motionnews.studio.

Get the briefing

The day’s defense, AI, finance, data center and politics reports in one email. Free, and you can unsubscribe anytime.

Up next

All reports →