OpenAI has issued a major apology to Australia after one of its artificial intelligence agents was found to have breached a Medicare statistics portal earlier this year.
The incident took place on June 18, when an OpenAI agent obtained unauthorised access to the portal after its initial request for information was rejected.
OpenAI identified the breach in August and notified Services Australia on September 10. Prime Minister Anthony Albanese disclosed the incident on Thursday.
In a blog post titled ‘how we will do better for Australia’, the AI company said: “We are sorry and working to do better in the future.”
OpenAI said the post would set out the steps it plans to take to “rebuild trust with the Australian people”.
“This is a new kind of cyber incident which represents an emerging global challenge,” the company said.
“One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.”
OpenAI said its investigation showed the incident was not isolated. Internal reviews found interactions involving several Australian government agencies, including the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare.

The breach occurred on June 18, when an OpenAI agent gained unauthorised access to a Medicare statistics portal after its initial request for information was denied (stock image)
The company said there was no evidence that individual Medicare records, patient files or identifiable health information had been accessed.
According to OpenAI, the experimental model had been assigned a research task focused on government spending on medicines for skin conditions in Victoria.
The model struggled to locate the relevant information through public sources before finding a way to access the non-public Medicare statistics service, the company said.
“It then used this access to review technical system information and source code related to the service, all still with the objective of trying to find the information it was originally looking for,” OpenAI said.
“We did not intend for this activity to occur, and the access to the service and follow-on activity should not have happened.”
OpenAI also acknowledged shortcomings in its handling of the incident, admitting that the affected agencies should have been notified earlier.
“Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” it said.
Since the breach, OpenAI said it has strengthened protections in its research environments by introducing network restrictions, upgrading monitoring systems and adding controls to prevent direct live internet access during model-training exercises.
The company has also paused training and evaluation programs involving tool use for its most advanced models while further safety measures are introduced.

OpenAI has created a new Australian taskforce to focus on local AI policy responses
As part of its response, OpenAI pledged dedicated assistance for the affected agencies, including funding and technical support to strengthen cyber defences. It will also establish a new Australian taskforce to develop policy recommendations for managing the risks created by advanced AI agents.
The taskforce will draw on independent Australian expertise and is expected to report by the end of the year.
Its priorities will include improving notification processes, strengthening coordination between governments and AI developers, and identifying extra safeguards to protect government systems.
OpenAI’s chief strategy officer, Jason Kwon, will also travel to Sydney next week to appear before the Joint Select Committee on Artificial Intelligence.
‘He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward,’ the company said.