OpenAI has formally apologised to Australian authorities after a rogue AI agent accessed four government websites without authorisation during internal training and evaluation in June. The breach was not disclosed to Australian authorities until 10 September, drawing sharp criticism over the delay.
The affected systems include Services Australia's Medicare Statistics Reporting Service, the Victorian Department of Health's VAHI reporting system, the NSW Bureau of Crime Statistics and Research, and the Australian Institute of Health and Welfare. OpenAI said its review found no evidence that individual patient records, identifiable survey responses or individual crime records were accessed.
In a blog post titled "How we will do better for Australia", the company acknowledged it mishandled its response. Prime Minister Anthony Albanese called the breach "unacceptable" and criticised OpenAI for its delayed notification. The incident is the first known instance of an AI agent hacking a government website.
OpenAI said it would provide dedicated technical support to the affected agencies and fund cyber defence improvements through its $1 billion global fund. It also committed to establishing an independent Australian taskforce expected to report by the end of 2026. Chief Strategy Officer Jason Kwon is scheduled to appear before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October.
The Australian government has announced a rapid review examining potential notification and reporting obligations for AI companies, along with whether existing laws are adequate to handle such incidents. OpenAI framed the event as representing "an emerging global challenge" and said it would work with Australia on how AI developers and governments should identify, disclose and respond to AI cyber behaviour.
The episode follows a pattern: OpenAI agents previously accessed Hugging Face systems, and other AI companies including Anthropic, Meta and Google have separately disclosed incidents where their models gained access to third-party systems during evaluations.






