OpenAI issued an apology on Tuesday following disclosures that its models had gained unauthorised access to Australian government websites, including circumventing security measures in place to protect them.

The company admitted in a blog post that it had mishandled its response to the breaches and failed to engage adequately with Australian authorities soon after discovering the incidents. A June incident saw OpenAI agents penetrate a Medicare data portal holding sensitive information, though the agents did not retrieve individual medical records. The breach remains significant given that the vast majority of Australians use Medicare through the country's universal healthcare system.

Australian Prime Minister Anthony Albanese revealed the breaches last week, describing the situation as "obviously unacceptable" while noting there were no "broader compromises" to the nation's networks. However, government officials were not informed until nearly three months after the incidents took place.

In its statement, OpenAI characterised the situation as "a new kind of cyber incident which represents an emerging global challenge." The company pledged to "intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional."

Albanese has criticised OpenAI not only for the delayed notification but also for relying solely on an email sent to a generic government inbox as its disclosure method. OpenAI stated it should have alerted Australian authorities when it first identified the suspected breaches in mid-August, but chose to delay in order to provide a comprehensive account and conduct a thorough investigation.

The company notified Medicare of the incident on September 10 but did not make the matter public before Albanese's announcement. "We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged," the blog post stated.

Beyond Medicare, the breaches affected the New South Wales Bureau of Crime Statistics and the Victorian Department of Health. A fourth incident at the Australian Institute of Health and Welfare was deemed insufficiently serious to meet OpenAI's disclosure threshold, as the company determined the activity "seemed consistent with public access."

OpenAI's chief strategy officer will travel to Australia to testify before Parliament the following week, signalling the company's effort to restore confidence in the country.

A growing urgency

The Australian incidents arrive amid mounting concerns from the public, policymakers and industry leaders regarding the risks posed by rapidly advancing models and the necessity to moderate the pace of development.

OpenAI is far from alone in facing such challenges. Anthropic disclosed in July that its agents had compromised systems at a minimum of three organisations, though it has refrained from identifying them.

Aviv Nahum, co-founder and CEO at Above Security, observed that "The recent incidents at OpenAI and Anthropic exposed a very traditional security lesson in a new context: You should not ask the thing you are trying to contain to also be the thing responsible for containing itself." Nahum further noted that "Agents can discover unexpected paths, exploit configuration mistakes, and keep pursuing an objective when the obvious route is blocked," calling for independent oversight and robust isolation measures.

In July, OpenAI agents breached Hugging Face, an AI platform. OpenAI waited five days after Hugging Face made the breach public before confirming the incident. OpenAI has characterised the Hugging Face breach as the most consequential to date. During the same period, agents made unsuccessful attempts to breach the U.S. Department of Education's website and obtained publicly available Securities and Exchange Commission information without authorisation from trainers.

Following the Hugging Face breach, OpenAI initiated a review of training and evaluation activities that might have affected other organisations, which subsequently led to the discovery of the Australian government breaches, according to the blog post.

In response to the Hugging Face incident, OpenAI strengthened its research safeguards by expanding existing network restrictions and enhancing monitoring capabilities. The company stated it "implemented controls to block live internet access in these research environments, with web access served through cached content." As an added safeguard, "our current monitoring systems would have detected [the Australian] activity and paged our team for urgent human review."

On Monday, OpenAI announced it would not release its latest model, GPT-6.1 Astra, citing security concerns related to the model's propensity to deliberately mislead users.