OpenAI apologises for Australia Medicare hack


OpenAI’s headquarters in San Francisco. OpenAI said its agents infiltrated a data portal containing information on Medicare, Australia’s public health insurance program, in June. — The New York Times

Speaking at a hearing before Australia’s Parliament on Oct 6, OpenAI’s chief strategy officer, Jason Kwon, apologised for the company’s artificial intelligence (AI) agents breaching government websites and accessing nonpublic data, and for taking months to notify Australian officials.

“That should not have happened,” he said. “We also should have handled our response better.”

OpenAI said its agents infiltrated a data portal containing information on Medicare, Australia’s public health insurance program, in June. The AI company discovered the breach in mid-August, but did not notify Australian officials until Sept 10, further drawing their ire.

The Australian government is investigating the breaches, including examining any legal consequences or the need for new AI regulations. The company’s models also attempted to access another federal agency, the Australian Institute of Health and Welfare, and two state government sites.

Since the Medicare breach, OpenAI has installed additional monitoring to allow for “immediate intervention” by staff to stop training if models access the Internet in ways they’re not supposed to, Kwon said. He said the company last week notified a state wildlife service agency within 48 hours after the company realised an incident had occurred.

“Because of the novelty of this situation, I think we have learned our lesson that it is better to inform, even with partial information,” he said.

(The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to AI systems. The two companies have denied those claims.)

Here’s what else to know:

– The hack: During internal training and evaluation of an “experimental” OpenAI model not intended for public release, AI agents tasked with researching public medicine spending carried out the hack, OpenAI said. The agents did not access individual medical information or patient records, the company said in a statement, but “took actions that we had not authorised it to take.”

– Earlier apology: The company acknowledged in late September that it had mishandled the response and said it would work to rebuild trust with Australians. It said it was working with Australia to “help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.”

– Other companies: Officials from Anthropic were questioned earlier at the Joint Select Committee hearing on artificial intelligence, while representatives from Microsoft and Google are also set to speak.

– Rogue activity: OpenAI’s models also in recent months meddled with websites for US government agencies – the Education Department, the Commerce Department and the Securities and Exchange Commission – without the company’s knowledge, though none of the incidents was breaches, according to the company. – ©2026 The New York Times Company

This article originally appeared in The New York Times.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read