OpenAI apologises for Australian government website hack, pledges to rebuild trust

Firm’s chief strategy officer to appear at an Australian Senate committee hearing on AI on Oct 6

Summarise
Published Tue, Sep 29, 2026 · 12:28 PM
    • The Australian government has announced a rapid review into the breach, examining potential notification and reporting obligations of AI companies.
    • The Australian government has announced a rapid review into the breach, examining potential notification and reporting obligations of AI companies. PHOTO: REUTERS

    [SYDNEY] OpenAI apologised for the hacking of an Australian government website by a rogue AI agent, committing funding to improve cyber defences and to establish a local response task force as scrutiny mounts over the high-profile incident.

    In a blog post on Tuesday (Sep 29) titled “How we will do better for Australia”, the ChatGPT maker acknowledged it mishandled its response and pledged to take accountability to “rebuild trust with the Australian people”.

    The incursion, which occurred in June but was not made public until Sep 24, is the first known instance of an AI agent hacking a government website.

    The incident alarmed Australia, drawing public condemnation and a sharp rebuke from Prime Minister Anthony Albanese, who called it “unacceptable” and criticised the company’s delay in notifying the government.

    “In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI said in the blog post. “We also should have handled our response better. We are sorry and working to do better in the future.”

    OpenAI said an experimental AI model breached the Services Australia Medicare Statistics Reporting Service, a data portal for the country’s universal healthcare system, during an internal training activity.

    Asean Intelligence

    Get insights into businesses across South-east Asia

    Get the free report

    “An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files,” the company said.

    But its review to date had not found any evidence of medical records being accessed from the portal, OpenAI said.

    AI agent activity affecting three other Australian government agency websites also did not result in access to sensitive records, according to the company.

    OpenAI said it would provide dedicated support for the affected agencies, finance the strengthening of cyber defences for government and industry through its US$1 billion global fund and establish an Australian task force to develop recommendations “drawing on lessons from these incidents”.

    It also confirmed chief strategy officer Jason Kwon would appear at an Australian Senate committee hearing on AI in Sydney on Oct 6.

    The Australian government has announced a rapid review into the incident, examining potential notification and reporting obligations of AI companies and the adequacy of its laws in dealing with such breaches.

    Separately, OpenAI has cancelled the release of its new AI model GPT-6.1 Astra after ​internal testing found the system did not meet the company’s safety standards. REUTERS

    Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.

    Share with us your feedback on BT's products and services