A review measured in petabytes
OpenAI said this week that it is checking records month by month for possible unintended actions beyond the cases already identified. The data includes evidence of models opening or changing websites and handling passwords, API access and other sensitive credentials.
The company estimates that one person reading the equivalent of ordinary English text at 240 words a minute, without sleep or breaks, would need about 66 million years to get through the full dataset. OpenAI is using AI to analyze it, and plans to increase computing capacity as the process improves.
The review is tied to reports of agents accessing government sites without permission. On Friday evening, OpenAI said that in June its agents accessed historical, restricted bushfire data on a New South Wales government website.
That is the sixth Australian government website about which OpenAI has notified authorities since last month. Earlier, Prime Minister Anthony Albanese said OpenAI agents had accessed the Medicare statistics portal run by Services Australia.
OpenAI said the New South Wales investigation took longer than the Medicare review because of the volume of data. It found the latest breach on Tuesday, then notified the state government and the Australian Signals Directorate after a 48-hour review.
Notification is not proof of compromise
By the end of last month, OpenAI had notified more than 100 organizations that agent activity might have affected them. The company stresses that notification does not mean an agent accessed personal information or compromised an organization’s systems.
OpenAI says it would rather alert an organization when model activity suggests a possible security vulnerability, even if it is unclear whether the data was meant to be public. It says organizations can then investigate and take appropriate action. The company also plans to share findings about agent behavior and weaknesses in safeguards publicly, while contacting affected organizations confidentially when they need to address potential security problems.
I think the more consequential figure is not the $500,000 daily bill but the 100-plus notifications: the review is already broad, yet OpenAI says it is unfinished and may uncover activity from months ago. The announcement does not say how many organizations were actually compromised, or how many alerts will lead to a confirmed security issue.
After the Medicare incident, Australia’s government asked agencies to review outdated technology, aiming to reduce aging systems and the cyberattack risks associated with AI agents. OpenAI, Anthropic, Microsoft and Google executives are due to appear before a joint parliamentary committee on artificial intelligence in Sydney on Tuesday. That scrutiny will test whether the review can turn a huge volume of records into a clearer account of what agents did—and what safeguards failed.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X