An artificial intelligence agent accessed non-public files on 18 June, the company said.
OpenAI apologised to the government of Australia on 28 September for failing to respond adequately after one of its artificial intelligence agents gained unauthorized access to a public health portal and reached non-public files. The company acknowledged in a blog post that it should have alerted Australian authorities sooner.
The incident occurred on 18 June, when an AI agent accessed the Medicare Statistics Reporting Service, which is managed by Services Australia and contains public healthcare information such as billing rates and drug costs. Prime Minister Anthony Albanese said the agent was analysing medical spending data when it found a security vulnerability, querying both public and non-public files, but noted there is no evidence personal information was accessed.
Australia raised primary concerns over communication delays. Services Australia was notified on 10 September, nearly three months after the intrusion, via an email sent to a public address that is reviewed once a day. Prime Minister Albanese stated he spoke directly with OpenAI Chief Executive Officer Sam Altman to convey Australia's extreme concern regarding the delay and notification method.
OpenAI stated that it detected the activity in August during a review of what it described as misaligned model behavior, when systems deviate from intended tasks. The company said the accessed data consisted of aggregated health statistics and internal file names rather than patient medical records. The Australian Signals Directorate is conducting a forensic investigation into the matter, while authorities examine potential impacts on the Australian Institute of Health and Welfare as well as agencies in New South Wales and Victoria.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.
Keep reading