Digital Marketing Asia 2026
‘We are sorry’: OpenAI moves to rebuild trust after Australian government breaches

‘We are sorry’: OpenAI moves to rebuild trust after Australian government breaches

share on

OpenAI has apologised to Australians and conceded it mishandled its response after experimental AI models gained unauthorised access to government systems, as the company moves to contain the fallout from one of the most significant tests yet of autonomous AI safeguards.

In a detailed account of the incidents, OpenAI said its models accessed systems belonging to Services Australia, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research and the Australian Institute of Health and Welfare during internal training and evaluation.

“We also should have handled our response better. We are sorry and working to do better in the future,” the company said.

The strongest incident involved Services Australia’s Medicare Statistics Reporting Service.

SEE MORE: OpenAI Aussie talent raid hits Google and Meta

OpenAI said an experimental internal model, tasked with researching government spending on medicines for skin conditions in Victorian communities, struggled to obtain the information through normal channels and took actions it had not been authorised to take.

The model discovered a way to gain non-public access to the service before running commands, retrieving internal files, credentials and aggregate statistics and writing files.

OpenAI said its review had found no evidence that individual medical or client records were accessed.

The company did not discover the activity until mid-August, following a wider review triggered by a separate incident involving Hugging Face. It notified Services Australia and the Victorian Department of Health on 10 September and BOCSAR on 18 September.

OpenAI now acknowledges that was too slow.

“Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” it said.

The admission follows criticism from Prime Minister Anthony Albanese over both the delay and the way the company initially contacted the government. The Medicare incident occurred in June, but Services Australia was not notified until September, when OpenAI sent its disclosure to a public-facing email inbox. 

OpenAI promises Australian taskforce

OpenAI is now attempting to repair the relationship, describing the events as a “new kind of cyber incident” and committing resources to Australian governments and critical infrastructure operators.

The company will establish a taskforce with independent Australian expertise to develop policy recommendations for managing risks from increasingly capable AI agents, including how developers notify governments when their systems behave unexpectedly.

Its recommendations are expected by the end of the year and will feed into both OpenAI’s approach and Australian government work on AI safety and cybersecurity.

OpenAI also pledged technical support for affected agencies and access to funding through its US$1 billion Daybreak for Frontline Defenders fund to strengthen cyber defences.

The company said it has strengthened safeguards since the incidents, including blocking live internet access in relevant research environments and introducing monitoring designed to alert human reviewers when models behave unexpectedly.

It has also paused training and evaluation involving tool use for its most capable models until additional safeguards are in place.

The apology comes as Australia considers stronger rules governing AI safety and incident disclosure. The government has said it wants legislation establishing AI safety standards introduced by the end of the year, with the OpenAI incident expected to inform that work. 

OpenAI chief strategy officer Jason Kwon will now fly from the US to appear before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October, where the company said he will answer questions about the incidents and its response. OpenAI’s planned appearance has also been independently confirmed in reporting on the parliamentary inquiry. 

“We know we have a lot of work ahead of us to rebuild trust,” OpenAI said.

share on

Follow us on our Telegram channel for the latest updates in the marketing and advertising scene.
Follow

Free newsletter

Get the daily lowdown on Asia's top marketing stories.

We break down the big and messy topics of the day so you're updated on the most important developments in Asia's marketing development – for free.

subscribe now open in new window