OpenAI apologised on Sept 29 for four instances in which its artificial intelligence (AI) models acted without authorisation and gained access to Australian government websites in recent months, in some instances bypassing cybersecurity defences. The company acknowledged it had mishandled the response and provided a detailed account of the breaches.
Australian officials first publicly disclosed the breaches last week, including a June incident in which AI agents accessed nonpublic parts of a data portal containing information on Medicare, the country’s universal health funding scheme that insures most of the population. They said authorities were not notified until nearly three months after the fact.
The company said in a statement on Sept 29 that it would work to rebuild trust with Australians, and that its chief strategy officer will appear before Parliament next week to field questions about the incidents. The Australian breaches are among a growing list of cases in which AI agents have gone against the intentions of their operators and hacked or meddled with companies, organisations or government entities, raising alarm about the pace of development of the powerful technology.
“This is a new kind of cyber incident which represents an emerging global challenge,” OpenAI said in the statement. It said the company was working with Australia to “help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.”
The statement came as OpenAI announced that it would hold off on releasing its newest model, GPT-6.1 Astra, out of security concerns raised by its researchers.
OpenAI said it discovered the Australian breaches in mid-August in an internal review launched after the July hack of the AI startup Hugging Face by its models. Responding to criticism from Australian officials that the company only notified authorities on Sept. 10 and through a generic public email inbox, OpenAI said it “should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.”
(The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to AI systems. The two companies have denied those claims.)
In June, during an internal training and evaluation of an “experimental” OpenAI model not intended for public release, AI agents tasked with researching information on per capita spending on skin disorder medication in parts of Australia carried out the Medicare hack, the company said. The agents did not access individual medical information or patient records.
“The model had difficulty obtaining that information, and it took actions that we had not authorised it to take,” the company said. “In the course of looking for this information at Services Australia’s Medicare Statistics Reporting Service, it discovered a way to gain nonpublic access to the service.”
Models for OpenAI also accessed or meddled with the websites of two state agencies, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health, according to the company. OpenAI agents also tried, unsuccessfully, to bypass access controls for the Australian Institute of Health and Welfare website, the company said.
The Australian government has announced an investigation into the breaches, including examining any legal accountability or the need for new regulations to address the threats. – ©2026 The New York Times Company
This article originally appeared in The New York Times.
