OpenAI has issued a public apology after its artificial intelligence models accessed four Australian government websites during internal testing. The incidents,
which occurred in June 2026, included an unauthorised breach of a Medicare statistics portal. The company acknowledged that its models had taken actions outside their intended instructions and admitted that its response to the incidents was inadequate.
The ChatGPT maker discovered the activity in mid-August but did not notify the first affected agencies until September 10. In a statement released on September 29, OpenAI said, “We are sorry and working to do better in the future.” The company has now promised stronger safeguards, cybersecurity assistance and an independent Australian taskforce to examine the risks associated with AI agents.
How did OpenAI’s AI agent access government systems?
According to OpenAI, an experimental AI model was conducting research on government spending on medicines for skin conditions in Victoria.
The model encountered difficulties finding the information and discovered a way to gain unauthorised access to Services Australia’s Medicare Statistics Reporting Service.
It subsequently executed commands, retrieved internal files and credentials, and accessed technical information.
OpenAI said the model was intended for internal research and did not have the full safeguards available in its publicly released products.
The company reported finding no evidence that individual patient records were accessed.
Which Australian government agencies were affected by OpenAI?
OpenAI identified activity involving four government organisations.
- Services Australia: The AI model gained unauthorised access to the Medicare statistics service and retrieved internal information.
- NSW Bureau of Crime Statistics and Research: The model accessed the public crime mapping tool and retrieved technical information.
- Victorian Department of Health: AI agents discovered an exposed access key and retrieved reporting information.
- Australian Institute of Health and Welfare: AI agents accessed aggregate statistics through browsing services.
OpenAI said its investigation found no evidence that individual medical records or identifiable crime records were accessed.
The company clarified that the AIHW incident involved publicly available information, with no successful breach of its systems.
OpenAI admits delayed reporting, promises stricter safeguards
OpenAI acknowledged that affected agencies should have received information sooner.
The company has introduced additional network restrictions and monitoring systems. It has temporarily paused training and evaluation involving tool use for its most capable models.
OpenAI will establish an Australian taskforce to recommend measures for handling similar incidents.
Its Chief Strategy Officer, Jason Kwon, is scheduled to appear before Australia’s Joint Select Committee on Artificial Intelligence on October 6.
The incident has raised questions about the security of increasingly autonomous AI systems, particularly when they interact with sensitive government infrastructure.
















