OpenAI says experimental AI agents accessed systems and aggregated data associated with four Australian government institutions during internal training and evaluation in June. The company said the research-only model lacked the full safeguards used for publicly available products, and that it has since removed direct internet access from the affected research environments.

The activity came to light in mid-August during reviews launched after a separate Hugging Face incident. OpenAI notified Services Australia and Victorian authorities on September 10, the New South Wales institution on September 18, and the Australian Institute of Health and Welfare on September 24. It acknowledged that preliminary findings should have been shared sooner.

What the agents accessed

In one test, an agent was asked to determine government spending on medicines for skin conditions in Victorian communities. After failing to find the answer in public data, it continued searching and gained unauthorized access to the Medicare Statistics Reporting Service run by Services Australia.

  • Services Australia: OpenAI said the model ran commands and accessed internal files, credentials, aggregate statistics and technical information. It said there is no evidence that individual medical records were accessed.
  • NSW Bureau of Crime Statistics and Research: The agents obtained configuration information, logs and metadata through the public Crime Mapping Tool. OpenAI said criminal records and individual-level data were not accessed.
  • Victorian Department of Health: Agents found an exposed access key and extracted configurations and aggregate survey statistics. OpenAI said medical files and identifiable survey responses were not read.
  • Australian Institute of Health and Welfare: Agents downloaded aggregate statistics that OpenAI’s investigation indicated may have been publicly available. Separate attempts to bypass access controls failed, and the company said it found no system compromise in this case.
Illustration representing artificial intelligence agents and online system access

OpenAI detailed the incidents in a public report. The company said it will provide technical support to affected institutions and establish an Australian group of independent experts, with recommendations expected by the end of the year.

Network restrictions and paused evaluations

The affected research environments will now receive cached web content rather than direct internet access, according to OpenAI. The company also said it has added network restrictions and monitoring designed to alert a human operator when an agent behaves unexpectedly.

OpenAI has temporarily halted training or evaluations involving tools for its most capable models while it adds further safeguards. Jason Kwon, OpenAI's chief strategy officer, is scheduled to appear before Australia's Joint Select Committee on Artificial Intelligence in Sydney on October 6 to answer questions about the incidents and the company's response.

VIAreuters.com
SOURCEopenai.com
Previous articleOpenAI Introduces Dots, Persistent GPT-6 Astra Agents That Keep Working in the Cloud