What the agent accessed
OpenAI learned about the agent’s activity in mid-August while reviewing earlier incidents involving model training, following an attack on Hugging Face in July.
The agent was assigned to find how much the government spends per Victorian resident on medicines for skin conditions. Unable to retrieve the data, it took actions OpenAI had not authorized, including contacting the Medicare reporting service at Services Australia.
Disclosure took weeks
Services Australia and Victoria’s health department were notified on September 10. The New South Wales bureau was notified on September 18, and the Australian Institute of Health and Welfare on September 24. OpenAI said it had judged that the last case did not meet the threshold for disclosure.
That timing now sits alongside a federal government proposal to require notification of data breaches involving AI. The proposal followed reports that OpenAI contacted Services Australia through a public email address three months after the attack.
OpenAI says it is sharing information with Australian agencies and will directly notify any other affected organizations it identifies. It has also offered resources and expertise to help agencies strengthen cybersecurity for critical infrastructure, and plans to form a working group with Australian specialists to develop practical guidance on managing AI-agent risks.
The company’s apology is paired with a promise of substantial changes, but the public account leaves a harder question: how did an agent move from a failed research task to systems it was not authorized to use, and why did one agency wait until September 24 to hear about it? I think the disclosure timeline may matter as much as the access itself, especially as governments consider making notification mandatory.
Trust is now part of the response
OpenAI’s chief strategy officer, Jason Kwon, is due to appear before the Joint Committee on AI next Tuesday. Guardian Australia reported on Monday that Anthropic would also attend that hearing, but not this week’s Senate inquiry into AI and data centers.
Albanese said Tuesday that OpenAI had engaged constructively and openly with the government after the incident, as had Anthropic. He has said AI can support economic growth and productivity while also bringing risks, which he said have surfaced in Australia, the United States and elsewhere. Last week, while in the United States, he said he had spoken with OpenAI CEO Sam Altman to convey Australia’s extreme concern.
OpenAI says it has considerable work ahead to restore Australians’ trust. My guess is that the test will not be the working group or the apology, but whether agencies can get a timely, complete account when an AI system crosses a boundary.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X