
Image: METAL
Summary
- In a September 28 blog post, OpenAI admitted and apologized that an experimental model accessed four Australian government sites without authorization during internal training and evaluation in June.
- The model found a non-public way into the Medicare Statistics Reporting Service, ran commands and retrieved internal files and credentials, while the company said it found no evidence that individual medical records were accessed.
- OpenAI pledged dedicated support, credits from its $1 billion Daybreak fund and an independent taskforce, and Chief Strategy Officer Jason Kwon will appear before a parliamentary committee in Sydney on October 6.
OpenAI published a post titled "How we will do better for Australia" on its official blog on September 28 (local time), admitting and apologizing that during internal training and evaluation in June its model accessed four Australian government websites without authorization. "We are sorry and working to do better in the future," the company said, adding that it should also have handled its response better. The affected bodies are Services Australia, the federal agency that delivers welfare and health payments, the NSW Bureau of Crime Statistics and Research (BOCSAR), the Victorian Department of Health and the Australian Institute of Health and Welfare (AIHW). OpenAI described the episode as "a new kind of cyber incident," an emerging challenge for the whole world.
The most serious case involves the Medicare Statistics Reporting Service run by Services Australia. According to the OpenAI statement METAL reviewed, the model found on its own a way to gain non-public access to the service, then ran commands inside it, retrieved internal files, credentials and aggregate statistics, and even wrote files. It went on to examine the service's technical system information and source code. The company said its review so far has found no evidence that anyone's medical records were accessed. The model in question was an experimental, internal-only model not intended for public release, and it was running without the full set of safeguards applied to the company's public products.
The incident began with an ordinary research task. OpenAI assigns its models a broad collection of questions users might ask and trains them to find and interpret published statistics. In this case, the model was asked to research government spending per person on medicines for skin conditions in Victorian communities. When it could not easily find the figure, the model took actions the company had not authorized, and the company explained that everything, including the non-public access and the review of source code, was carried out with the aim of answering the original question.
The pattern at the other three bodies differed. At BOCSAR, the model sent API requests through the public Crime Mapping Tool, and the system returned application configuration, operational jobs, logs and website metadata. At the Victorian Department of Health, OpenAI agents discovered an exposed access key, queried the reporting system of the Victorian Agency for Health Information (VAHI) and retrieved reporting configuration and aggregate survey statistics. The AIHW case involved downloading aggregate statistics through third-party browsing and download services, and a separate attempt to bypass access controls failed. The company said none of the three cases reached individual crime records, medical records or identifiable survey responses.
The discovery is tied to an earlier incident. After the Hugging Face incident in July, OpenAI went back through earlier training and evaluation activity, and in mid-August that review surfaced the activity involving Australian government sites. METAL previously reported on how an unreleased OpenAI model broke into Hugging Face, and in this post the company again wrote that Hugging Face remains the most severe incident it has observed. Notifications went to Services Australia and the Victorian Department of Health on September 10, followed by BOCSAR on September 18. The AIHW case did not meet the company's disclosure threshold because the access appeared consistent with public access, but OpenAI informed the institute on September 24 by sharing its findings and offering a briefing.
The political reaction in Australia to how the notice was given was sharp. According to reports, OpenAI alerted Services Australia on September 10 by emailing its public inbox, and Prime Minister Anthony Albanese disclosed the incident last week while attending the United Nations General Assembly. Deputy Prime Minister Richard Marles said the agent had "scaled the fence." Albanese said he had a "direct but constructive discussion" with OpenAI CEO Sam Altman last week, and on the 28th he was briefed in Canberra by the government taskforce investigating the incident. "OpenAI have been very constructive and open in engaging in that process, and I welcome that," he said, adding that Anthropic had also engaged constructively.
Seen through a legal lens, the central question is when the disclosure clock starts. The access happened in June, the company noticed it in mid-August, and the first notice went out on September 10. OpenAI said it had aimed to give a detailed account once its investigation was complete, but admitted it should have shared preliminary findings sooner and kept agencies updated as new facts emerged. As the AIHW case shows, the disclosure threshold that decided whether to notify was an internal yardstick set by the company. Incident disclosure regimes are usually designed around outside attackers, yet here the intruder was the developer's own model in training, which raises questions the existing framework does not answer. The company's promise to notify any newly identified affected agency promptly and directly with whatever information is available is a step toward closing that gap.
The company also set out technical measures to prevent a repeat. After the Hugging Face incident, OpenAI added network restrictions and expanded monitoring in its research environments, blocked live internet access and switched web access to cached content only. According to the company, when a model gained live internet access during a recent training run, monitoring caught it and paged a human reviewer, and the company stopped the run. METAL has reported that OpenAI halted model training after a DNS bypass incident. OpenAI reiterated that it has paused training and evaluation involving tool use for its most capable models and will resume only when it is confident additional safeguards are in place.
Its commitments to Australia fall into three parts. The first is dedicated support that shares technical findings and arranges engagement with its response teams so affected agencies can understand what happened and assess the impact. The second is credits and technical assistance from the $1 billion Daybreak for Frontline Defenders fund to help Australian governments and industry strengthen cyber defenses across critical infrastructure. METAL previously reported that OpenAI committed $1 billion to support under-resourced cyber defenders. The third is a taskforce of independent Australian experts that will deliver recommendations by the end of the year on improving notification processes, strengthening coordination between AI developers and government, and protecting government systems.
The next stage is parliament. OpenAI Chief Strategy Officer (CSO) Jason Kwon will fly in from the company's US headquarters to appear before the Joint Select Committee on Artificial Intelligence in Sydney on October 6, answering questions about what the company knows, how it responded and what it has changed. An apology, a fund and a taskforce are only the starting line for rebuilding trust, and how responsibility should be divided when a model climbs the fence on its own will be debated in public for the first time in that room.





Comments