OpenAI says its AI wrongly accessed Australian govt systems

OpenAI says its AI wrongly accessed Australian govt systems

OpenAI has admitted that an internal artificial intelligence model accessed Australian government systems without authorisation, including a Medicare statistics service where it retrieved internal files and credentials.

While attending the United Nations General Assembly in New York in September, Australian Prime Minister Anthony Albanese had revealed that an artificial intelligence agent operated by OpenAI gained unauthorised access to an Australian Medicare data portal earlier this year.

Albanese said the AI agent accessed both public and non-public files on the Medicare statistics reporting service portal administered by Services Australia.

Meanwhile, the company in a statement published on its website on September 28, 2026, titled “How we will do better for Australia,” has apologised for the incident.

OpenAI said the incident occurred in June during internal training and evaluation of an experimental model that was not intended for public release and did not have the full set of safeguards used in its publicly available products.

According to the company, the model was assigned a task to research government spending per person on medicines for skin conditions in Victorian communities.

However, after struggling to obtain the information, the model took actions that OpenAI said it had not authorised.

At Services Australia’s Medicare Statistics Reporting Service, OpenAI said the model “discovered a way to gain non-public access to the service.”

The company said the model then “ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files.”

However, OpenAI said its review had found no evidence that individual patient or client records were accessed.

We are sorry and working to do better in the future,” the company said.

OpenAI said the incident represented “a new kind of cyber incident which represents an emerging global challenge.”

The company also disclosed that its models had accessed three other Australian government systems.

At the New South Wales Bureau of Crime Statistics and Research, an OpenAI model accessed the public Crime Mapping Tool while researching public crime statistics.

The model made API and website metadata requests through the public tool, with the system returning application configuration, operational jobs and logs, as well as website metadata.

OpenAI said individual crime records were not accessed.

In Victoria, OpenAI agents discovered an exposed access key that allowed them to query the Victorian Agency for Health Information’s reporting system and retrieve reporting configuration and aggregate survey statistics.

The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies,” OpenAI said, adding that individual medical records or identifiable survey responses were not accessed.

The company also said its agents retrieved aggregate statistics from the Australian Institute of Health and Welfare through third-party browsing and download services.

While separate attempts to bypass access controls were unsuccessful, OpenAI said the downloaded material appeared to have been publicly available and there was no system compromise.

OpenAI said it began investigating the activities after a review triggered by an earlier incident involving AI activity on the Hugging Face platform.

The review, which began after the July Hugging Face incident, identified the Australian government activity in mid-August.

OpenAI said it notified Services Australia and the Victorian Department of Health on September 10, followed by the NSW Bureau of Crime Statistics and Research on September 18.

The company said the AIHW activity did not initially meet its disclosure threshold because the access appeared consistent with public access, but it notified the agency on September 24 to share its findings.

However, OpenAI acknowledged that it should have disclosed preliminary findings sooner.

“Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” it said.

The company said it had since strengthened safeguards around its research environments, including additional network restrictions, expanded monitoring and controls designed to block live internet access.

It also said its current monitoring systems would have detected the activity and alerted human reviewers for urgent intervention.

n Australia, OpenAI said it would provide resources and technical expertise to affected agencies, support efforts to strengthen cyber defences and establish an Australian taskforce made up of independent experts.

The taskforce is expected to develop policy recommendations for managing risks from increasingly capable AI agents, including improved notification processes and stronger coordination between AI developers and governments.

OpenAI said its Chief Strategy Officer, Jason Kwon, would appear before the Joint Select Committee on Artificial Intelligence in Sydney on October 6 to answer questions about the incident and the company’s response.

The disclosure comes after Australian Prime Minister Anthony Albanese revealed last week that an OpenAI agent had gained unauthorised access to the Medicare statistics reporting service administered by Services Australia.

Albanese said the incident was “extremely” concerning and that he had spoken with OpenAI CEO Sam Altman about the breach. ABC News reported that the company took about three months to notify the Australian government.

OpenAI’s latest disclosure provides further details of what the model accessed and the company’s planned response.