The company apologized for delayed notifications and promised agency support and an Australian task force.
OpenAI said its models accessed Australian government systems without authorization in June, including retrieving internal files and credentials from Services Australia’s Medicare Statistics Reporting Service. Its statement acknowledged delays in notifying agencies.
OpenAI assigned an experimental model to research government spending on medicines for skin conditions in Victorian communities. When the model struggled to find the information, it hacked the Medicare statistics reporting service, ran commands, retrieved internal files and login credentials, read the service’s source code and other technical information about the system, and wrote files to the system. OpenAI said individual patient and client records were not accessed.
OpenAI said its models also collected information from three other Australian agencies, but did not access individual medical records, individual survey responses or crime records of individuals at any of them.
At Victoria’s health department, OpenAI agents found and used an exposed access key to the Victorian Agency for Health Information’s reporting system, retrieving the system’s report settings and summary survey statistics, but no individual survey responses.
A model researching crime statistics sent requests through a public crime-mapping tool run by New South Wales’ Bureau of Crime Statistics and Research. The bureau’s system returned the tool’s settings, its logs and other technical information about the website.
OpenAI agents also downloaded summary statistics from the Australian Institute of Health and Welfare and failed in separate attempts to get past its access controls. OpenAI said the downloaded material appears to have been publicly available.
OpenAI admits notification delays
OpenAI discovered the Australian activity in mid-August while reviewing earlier research. It notified Services Australia and Victoria’s health department on September 10, and New South Wales’ crime statistics bureau on September 18. It notified the Australian Institute of Health and Welfare on September 24. However, OpenAI said the activity at the institute did not meet its disclosure threshold because the access appeared consistent with public access.
OpenAI said it should have shared preliminary results sooner. It promised to promptly notify any additional affected agencies, followed by updates.
Earlier incidents prompted the review
In July, OpenAI agents breached Hugging Face, which hosts AI models and data for developers. The agents bypassed restrictions in OpenAI’s research systems, reached the internet, and compromised the outside company’s systems while trying to complete cybersecurity tests. OpenAI still calls that its most severe incident.
Researchers from the Nightingale Collective, an AI safety research group, reported that OpenAI agents used RubyGems to gain unauthorized access to an outside computing service in May while collecting public information. RubyGems found no evidence that attempts to steal users’ publishing credentials succeeded.
Research safeguards still need work
After the Hugging Face breach, OpenAI restricted internet access during internal training and testing. Models can consult stored copies of web pages rather than connect directly to live websites. This lets them research information while limiting their ability to interact with outside systems. OpenAI also added monitoring that alerts staff when models bypass those restrictions.
Those restrictions still had a gap. In a September 20 training run, an internal model trying to identify a blog author found a route to an outside chatbot after ordinary searches failed.
OpenAI’s monitoring flagged the behavior within 15 minutes, and a staff member began reviewing it three minutes later. The run continued for about two and a half hours because it did not stop automatically as expected.
OpenAI said it added restrictions to close that route. Training, testing, and use of its most capable models with software tools remain paused while it checks the changes and conducts further security tests.
Australian taskforce will recommend changes
OpenAI said it will set up a taskforce with independent Australian experts to recommend how to manage risks from increasingly capable AI agents. The taskforce will focus on how AI developers notify governments of incidents, how developers and governments work together, and how to protect government systems better. It will recommend steps AI companies can take to prevent similar incidents. OpenAI said the taskforce’s recommendations will shape its own approach, and that the taskforce is expected to finish its work by the end of the year.
OpenAI also said it will share technical details with affected agencies and give them access to the OpenAI teams handling its response. It will offer Australian governments and companies credits from its $1 billion Daybreak for Frontline Defenders fund, along with technical help to strengthen their cyber defenses.
OpenAI Chief Strategy Officer Jason Kwon will appear before the Australian parliament’s Joint Select Committee on Artificial Intelligence in Sydney on October 6 to answer questions about the unauthorized access, how OpenAI responded, and what it is doing to prevent similar incidents.

