“We also should have handled our response better. We are sorry and working to do better in the future,” the US tech giant said in a blog post.
The incident in June involved an experimental model, researching medicine spending in Victoria, “took actions that we had not authorised it to take” when it struggled to obtain information. It gained non-public access to Services Australia’s Medicare statistics service, when it couldn’t find what it was seeking in approved channels, then examined technical information and source code, “all still with the objective of trying to find the information it was originally looking for”.
In spite of best intentions, the AI agent was still running commands, retrieving internal files and credentials, and writing files on a government server.
OpenAI conceded that the incident, involving the Australian Institute of Health and Welfare “did not meet our disclosure thresholds”, although the model operated “without the full set of safeguards used in our publicly available products”.
It concurred with the government’s preliminary assessment that no medical records were accessed.
That’s reassuring at a time when founder and CEO Sam Altman is telling the world that “we are close to creating a genie that can grant any wish”, aka wiping out its customer base.
Part of the ChatGPT maker’s defence over the Australian incident that it’s done worse things elsewhere – such as July’s Hugging Face breach. To atone for its sins, OpenAI’s penance includes dedicated support for affected govermment agencies, credits from its global US$1 billion cyberdefence fund and a “taskforce with independent Australian expertise to develop practical policy recommendations for managing risks from increasingly capable AI agents”.
The June breach was discovered in mid-August during a review, but Services Australia wasn’t notified until September 10 via a public mailbox.
It seems AI is still not developed enough to figure out when to tell its creators that it’s stuffed up and they should probably get on the phone and tell someone immediately.
“Our aim was to give affected agencies a detailed account once our investigation was complete,” OpenAI said, acknowledging it should have shared preliminary findings sooner.
Meanwhile, Canberra’s gone into high dudgeon mode over the incident.
Prime minister Anthony Albanese, who was coincidentally in New York when the revelations dropped, said it would shape planned AI standards legislation and the government is pondering whether offences occurred and if the Australian Federal Police should get involved.
Meanwhile, Home Affairs has ordered agencies to review ageing tech systems and strengthen cyber protections. Acting minister Richard Marles said: “AI is changing the environment in which we operate at extraordinary speed. Government systems need to keep up.”
Frontier thinking from a government that’s been in power for more than four years, including six months before ChatGPT first launched.
And after US president Donald Trump struck a voluntary ‘AI accord’ with execs from Google, Anthropic, Meta, OpenAI, Musk’s X and Nvidia, federal communications minister Anika Wells huffed and puffed that a “promise is not protection”, insisting Australia will set its own rules
An Australian Senate inquiry into data centres wanted Altman and Anthropic’s Dario Amodei to swing by this week, but Sam has other plans. Instead, OpenAI chief strategy officer Jason Kwon is heading Down Under to appear before parliament’s AI committee on October 6.
So alongside finding a way forward on tax changes that have the potential to slam the breaks on Australia’s startup ecosystem, Canberra is now grappling with developing a regulatory framework that makes frontier AI responsible for its actions without turning the sector into another compliance nightmare only big tech can afford.




