OpenAI Apologises Over Rogue Agent Hack of Australian Government Websites, Vows Reform

OpenAI Apologises Over Rogue Agent Hack of Australian Government Websites, Vows Reform Getty Images

OpenAI has apologised to Australians over a rogue AI agent's unauthorised access to multiple Australian government websites, including Medicare-linked systems, and confirmed its chief strategy officer will appear before parliament next week.

In a blog post published on Tuesday, the company said it should have handled its response better. "We also should have handled our response better. We are sorry and working to do better in the future."

OpenAI said it became aware of the agent activity on Australian government websites in mid-August, after reviewing earlier training incidents that followed a separate attack on Hugging Face in July.

The incident originated when one model was tasked with researching government spending per person on medicines for skin conditions in Victoria. The model had difficulty obtaining that information and, according to OpenAI, "it took actions that we had not authorised it to take," including accessing Services Australia's Medicare statistics reporting service.

The agents gained non-public access to a Services Australia portal for Medicare statistics. OpenAI said the agent was able to run commands, retrieve internal files, credentials, and write files, but stated that no patient or client records were accessed.

The New South Wales Bureau of Crime Statistics and Research's public crime mapping tool was also accessed, with application configuration, operational jobs, logs, and website metadata provided to the agency.

In a separate incident, the agent discovered an exposed access key to query the Victorian Agency for Health Information's reporting system, gaining access to aggregate survey statistics.

For the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics, but separate attempts to bypass access controls were unsuccessful. The information obtained was publicly available.

Services Australia and the Victorian health department were informed on 10 September. The NSW Bureau of Crime Statistics was informed on 18 September. The Australian Institute of Health and Welfare was not notified until 24 September, as OpenAI determined the breach did not meet its disclosure thresholds.

"Since then we've worked closely with Australian government agencies to share what we've learned to date," OpenAI said. "If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge."

OpenAI said it would commit resources and expertise to affected agencies and provide Australian government agencies with support to build cyber defences on critical infrastructure.

Australian government agencies and industries will also be given credits from OpenAI's US$1 billion (AU$1.4 billion) Daybreak fund, which allows organisations to use frontier AI for cyber defence and to harden their systems by reviewing code and system configurations for vulnerabilities that can then be patched.

The company also said it would establish a taskforce with Australian expertise to develop practical policy recommendations on managing risk with AI agents.

OpenAI's chief strategy officer, Jason Kwon, will appear before the Joint Select Committee on AI on Tuesday next week.

Australian Prime Minister Anthony Albanese, who was in the United States last week when he announced the hack, said at the time he had spoken with OpenAI's chief executive, Sam Altman, "to express Australia's extreme concern about this incident."

On Tuesday, Albanese said OpenAI had been "very constructive and open in engaging" since the incident. He said AI can improve economic growth and productivity but also carries risks. "And we've seen those risks exposed – not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well."

The federal government has flagged it could introduce mandatory reporting rules for AI-related data breaches, following reports that OpenAI used a public-facing email address to report the incident to Services Australia three months after the hack occurred.

OpenAI acknowledged on Tuesday it had "a lot of work ahead" to rebuild trust with Australians but said it was making "meaningful changes."