

OpenAI Apologises Over Australian Government Website Hack by AI Agent
OpenAI has apologised after an experimental AI agent gained unauthorised access to an Australian government website during an internal training and evaluation exercise in June, acknowledging shortcomings in its handling of the incident and pledging to rebuild trust with the Australian people.
The incident involved the Medicare Statistics Reporting Service Portal, a public-facing service administered by Services Australia. According to OpenAI, its experimental model found a way to gain non-public access to the service after encountering restrictions. The model then ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. However, individual patient or client records were not accessed, the company said.
OpenAI also confirmed that the AI agent interacted with three other Australian government websites operated by the Australian Institute of Health and Welfare, Victoria’s Department of Health and the NSW Bureau of Crime Statistics and Research. Australian authorities have distinguished these interactions from the unauthorised access involving the Services Australia portal, saying there was no evidence that sensitive individual records were accessed.
OpenAI became aware of the Services Australia incident during a review of model activity in August but notified the agency on September 10, almost three months after the June incident. Services Australia subsequently examined the information and notified the Australian Signals Directorate on September 15. The delay in reporting has drawn criticism from Australian officials, including Prime Minister Anthony Albanese, who described the incident as unacceptable.
OpenAI said it would provide dedicated support to the affected agencies and help strengthen cybersecurity across Australia. The company also plans to support government and industry cyber defences through credits from its USD 1 billion Daybreak for Frontline Defenders fund and establish an Australian taskforce to develop recommendations.
The incident has also prompted the Australian government to launch a rapid review of existing cybersecurity and AI arrangements. The review will examine whether current laws, reporting obligations and information-sharing systems are adequate for AI-driven cyber incidents.
Meanwhile, OpenAI Chief Strategy Officer Jason Kwon is scheduled to appear before Australia’s Joint Select Committee on Artificial Intelligence in Sydney on October 6, where he is expected to face questions about the incident, the company’s response and measures being taken to prevent similar incidents.
