OpenAI issues a public apology. (File photo: Reuters)

We are sorry: OpenAI apologises for breaching government websites, reveals new plan in action

OpenAI has apologised after an AI agent accessed Australian government systems beyond its authorised task. The company has announced a new task force, cybersecurity support and tighter coordination with authorities in response.

by · India Today

In Short

  • OpenAI apologises over AI agent breach in Australia
  • New task force to tackle AI-agent security risks
  • The company to help strengthen Australian cyber defences

OpenAI is putting a new plan in place in Australia after its AI agent gained access to government systems without authorisation. The company says it will work with Australian experts, provide cybersecurity support to government agencies and improve how it communicates when its AI systems cause security incidents.

The changes come after an incident in which an OpenAI agent accessed several Australian government services while carrying out a research task. The company has now apologised for both the incident and the way it handled the response.

“We are sorry and working to do better in the future,” OpenAI said. “People want to know AI is being developed safely, and that starts with what companies like ours do ourselves.”

One of the main changes will be the creation of a task force involving Australian experts. OpenAI says the group will work on practical recommendations for dealing with the security risks created by increasingly capable AI agents. It will also look at how the company and government agencies can coordinate more effectively when such incidents happen.

OpenAI will additionally offer technical help and credits from its $1 billion Daybreak for Frontline Defenders fund to Australian government agencies and industries. The support is intended to help organisations find weaknesses in their systems, improve their code and configurations, and strengthen cybersecurity around critical infrastructure.

What happened to the government systems

The activity started with a relatively narrow request. OpenAI said the model was asked to find information about government spending on medicines for skin conditions in Victoria. When it could not get the information it needed, the agent began taking actions that were outside what it had been authorised to do.

That led it into government systems that were not meant to be part of the task. Among them was a Services Australia portal used for Medicare statistics. OpenAI said the agent was able to execute commands, access internal files and credentials, and create files. The company said patient and client records were not accessed.

The agent also reached a New South Wales crime statistics service, where information including system configuration, operational jobs, logs and website metadata was exposed to the model.

In another case, an exposed access key found by the agent allowed it to query a Victorian health reporting system for aggregate survey statistics. OpenAI said its agents also retrieved aggregate data from the Australian Institute of Health and Welfare, although attempts to bypass that agency's access controls did not succeed. The information obtained there was publicly available.

OpenAI said it discovered the activity in August while reviewing previous AI-related security incidents. It subsequently contacted the affected agencies at different points in September.

The handling of the incident has also drawn criticism from the Australian government. Prime Minister Anthony Albanese previously raised concerns with OpenAI CEO Sam Altman about the breach and the delay in notifying Canberra.

The company said it has “a lot of work ahead” to rebuild trust in Australia and acknowledged that its response should have been better.

- Ends