OpenAI has apologised for an AI agent’s unauthorised access to Australian government websites and pledged to rebuild trust with Australians, while committing resources to strengthen cybersecurity and establishing a local task force.
The company said Tuesday that an internal AI model, during a training exercise in June, gained non-public access to Services Australia’s Medicare Statistics Reporting Service. The model ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files, OpenAI said.
OpenAI said its investigation had found no evidence that medical or personal records were accessed. The model also interacted with three other government websites, where the company said it either accessed public or aggregate information or failed to bypass controls.
“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI said. “We also should have handled our response better. We are sorry and working to do better in the future.”
OpenAI said it would support affected agencies, help strengthen cyber defences and establish an Australian task force to develop recommendations on managing risks from AI agents.
The Australian government has launched a rapid review of its arrangements for AI-related cyber incidents.

