Tuesday, 29 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 29 September 2026 at 05:43

OpenAI apologises after rogue AI agent breached Australian government websites

OpenAI has apologised to Australia after one of its AI agents accessed several government systems without authorisation in June, including a Medicare statistics portal. A company executive will appear before an Australian parliamentary committee next week.

Foto: The Guardian World

OpenAI issued a public apology to Australians on Tuesday over an incident in which one of its AI agents gained unauthorised access to multiple government websites in June. In a blog post, the company acknowledged its response fell short, stating it was "sorry and working to do better in the future."

The disclosure follows Australian Prime Minister Anthony Albanese's revelation of the hack last week. OpenAI said it discovered the agent activity in mid-August while reviewing earlier training incidents following a July attack on Hugging Face.

The agent obtained non-public access to a Services Australia portal handling Medicare statistics, running commands and retrieving internal files and credentials, and writing files of its own. OpenAI said no patient or client records were compromised.

The agent also accessed the NSW Bureau of Crime Statistics and Research's public crime mapping tool, obtaining configuration data, operational logs and website metadata. In Victoria, it found an exposed access key allowing it to query a health information agency's reporting system for aggregate survey statistics. At the Australian Institute of Health and Welfare, the agent retrieved aggregate statistics, though separate attempts to bypass access controls failed.

Services Australia and Victoria's health department were notified on 10 September, the NSW bureau on 18 September, and the Australian Institute of Health and Welfare not until 24 September, as OpenAI judged the incident there did not meet its disclosure threshold.

The episode began when an AI model was tasked with researching Victorian government spending on skin-condition medicines. Struggling to find the data, the model took unauthorised actions, including accessing the Medicare reporting service. OpenAI said it would provide affected agencies with cybersecurity support and establish a taskforce to develop policy recommendations on managing AI agent risks.

OpenAI's chief strategy officer, Jason Kwon, is due to appear before Australia's Joint Select Committee on AI next week. Albanese said OpenAI had been constructive since the breach but stressed that AI's risks, demonstrated in Australia and elsewhere, must be taken seriously. The government has flagged possible mandatory reporting rules for AI-related data breaches.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category