OpenAI has acknowledged that an experimental artificial intelligence model accessed several Australian government systems without authorisation, including a Medicare statistics portal where it retrieved internal files and credentials.
The company disclosed the incident in a statement published on September 28, 2026, apologising to Australian authorities and describing the activity as an emerging form of cyber incident associated with increasingly capable AI agents.
The disclosure followed comments by Australian Prime Minister Anthony Albanese, who revealed during the United Nations General Assembly in New York that an OpenAI-operated AI agent had gained unauthorised access to the Medicare Statistics Reporting Service administered by Services Australia.
According to OpenAI, the incident occurred in June during internal training and evaluation of an experimental model that was not intended for public release and did not have the full safeguards deployed in its publicly available products.
The model had been tasked with researching government spending per person on medicines for skin conditions in Victorian communities.
After struggling to obtain the required information, however, the model took actions that OpenAI said it had not authorised.
At the Services Australia Medicare statistics portal, the company said the model “discovered a way to gain non-public access to the service.”
It subsequently ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files.
OpenAI said its investigation found no evidence that individual patient or client records were accessed.
“We are sorry and working to do better in the future,” the company said.
The company also disclosed unauthorised activity involving three other Australian government systems.
At the New South Wales Bureau of Crime Statistics and Research, an OpenAI model accessed the public Crime Mapping Tool while researching crime statistics.
OpenAI said the model made application programming interface and website metadata requests through the public service, resulting in the retrieval of application configuration, operational jobs and logs, as well as website metadata.
It said individual crime records were not accessed.
In Victoria, OpenAI said its agents discovered an exposed access key that enabled them to query the Victorian Agency for Health Information’s reporting system.
The agents retrieved reporting configuration and aggregate survey statistics.
“The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies,” OpenAI said, adding that individual medical records and identifiable survey responses were not accessed.
The company further disclosed that its agents retrieved aggregate statistics from the Australian Institute of Health and Welfare through third-party browsing and download services.
OpenAI said separate attempts to bypass access controls were unsuccessful, while the material downloaded from the AIHW appeared to have been publicly available and did not involve a compromise of the system.
The company said it began investigating the activity following a review triggered by an earlier incident involving AI activity on the Hugging Face platform.
The review, which began after the July incident, identified the Australian government activity in mid-August.
OpenAI said it notified Services Australia and the Victorian Department of Health on September 10, followed by the NSW Bureau of Crime Statistics and Research on September 18.
The company said it did not initially consider the AIHW activity to meet its disclosure threshold because the access appeared consistent with publicly available information. It nevertheless notified the agency on September 24 after completing its assessment.
OpenAI acknowledged that it should have informed the affected agencies sooner.
“Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” the company said.
The company said it had since strengthened safeguards around its research environments, including tighter network restrictions, expanded monitoring and controls intended to prevent live internet access.
It added that its current monitoring systems would have detected the activity and alerted human reviewers for urgent intervention.
In response to the incidents, OpenAI said it would provide affected Australian agencies with technical expertise and resources, support efforts to strengthen their cyber defences and establish an Australian taskforce comprising independent experts.
The taskforce is expected to develop recommendations for managing risks associated with increasingly capable AI agents, including improved incident-notification procedures and stronger coordination between AI developers and governments.
OpenAI’s Chief Strategy Officer, Jason Kwon, is scheduled to appear before the Joint Select Committee on Artificial Intelligence in Sydney on October 6 to answer questions about the incident and the company’s response.
Albanese had earlier described the unauthorised access to the Medicare statistics service as “extremely” concerning and said he had spoken with OpenAI Chief Executive Officer Sam Altman about the matter.
The latest disclosure provides further details about the systems accessed, the information retrieved and measures OpenAI says it is taking to prevent similar incidents.



