‘Do better for Australia’: OpenAI apologizes for unauthorized access

Direct Source Verification: This story is aggregated from POLITICO Europe (politico.eu). Full reporting rights and copyright belong to the primary publisher.
OpenAI agents searched for health spending data, leading to Medicare breach

CANBERRA — OpenAI has apologized to Australia for unauthorized access to Medicare statistical data by its agents and its handling of the incident, promising to do better and rebuild trust with the Australian public.

OpenAI broke its silence about the June incident, which it described as artificial intelligence models accessing Australian government websites “in ways they were not authorized to do” during internal training and evaluation.

“We are sorry and working to do better in the future,” OpenAI said in a statement.

“This is a new kind of cyber incident which represents an emerging global challenge. One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behavior, whether malicious or unintentional.”

Australian Prime Minister Anthony Albanese responded to the apology Tuesday, saying he had a “direct but constructive discussion” with OpenAI chief executive Sam Altman. “OpenAI have been very constructive and open … and I welcome that.”

OpenAI explained the incident occurred because it asked its model to research government spending per person on medicines for skin conditions in Victorian communities, when it discovered a way to gain non-public access to Medicare data held by Services Australia.

“We did not intend for this activity to occur, and the access to the service and follow-on activity should not have happened,” it said.

OpenAI said it will establish a taskforce with independent Australian expertise to improve processes including notification, to report by the end of 2026.

The company will also offer credits through a $1 billion Daybreak for Frontline Defenders fund the company announced Sept. 3, and technical assistance to strengthen cyber defenses across critical infrastructure.

Albanese revealed the incident in New York last week ahead of a United Nations speech rallying for greater regulation of AI. In addition to parliamentary inquiries, the Australian government has launched a taskforce to examine the incident. Critics have called for a compulsory notification regime and stricter penalties.

OpenAI explained that it began reviewing training activity in July in response to the Hugging Face incident, identifying in mid-August that Australian government websites had been affected.

With respect to the access of Medicare statistics on a Services Australia portal, OpenAI said its model had “discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. However, individual patient or client records were not accessed.”

It confirmed that the NSW Bureau of Crime Statistics and Research (BOCSAR), Victorian Department of Health: and Australian Institute of Health and Welfare (AIHW) were also affected. Services Australia and the Victorian department were notified on Sept. 10, BOCSAR on Sept. 18, and the AIHW on Sept. 24 because “the way it was accessed seemed consistent with public access”.

“Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date. If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.”

OpenAI listed a series of safeguards it has adopted since the Hugging Face incident, including urgent human review added when unauthorized access is detected and pausing its most capable models.

“We have joined organizations across technology, cybersecurity and critical infrastructure in a call for collective action on cyber defense. That call starts with our own responsibilities including stronger safeguards, timely disclosure and practical support for affected organizations. It also calls for investment in the teams protecting essential services, so they can find vulnerabilities, verify fixes and share what works.”

Original Source
https://www.politico.com/news/2026/09/28/do-better-for-australia-openai-apologizes-for-unauthorized-access-01096507?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication
Visit POLITICO Europe ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business