OpenAI apologises to Australia for AI breaches

'We are sorry and working to do better in the future'

OpenAI apologises to Australia for AI breaches

OpenAI has issued an apology to Australia for the unauthorised access of government websites by its AI agents, admitting that it could have handled its response to the incident better.

The AI firm's apology comes after Prime Minister Anthony Albanese made the incident public last week, while calling out OpenAI for taking too long to disclose the breach.

"We also should have handled our response better. We are sorry and working to do better in the future," OpenAI said in a blog post on Monday.

According to the AI firm, its aim was to give affected agencies a detailed account once its investigation was complete.

"However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerge," it added.

OpenAI said it identified the unauthorised access by its agents in mid-August 2026 when it reviewed earlier training and evaluation activity following the incident with Hugging Face in July 2026.

Four Australian government agencies' websites were affected. They include Services Australia, the New South Wales (NSW) Bureau of Crime Statistics and Research (BOCSAR), the Victorian Department of Health, and the Australian Institute of Health and Welfare (AIHW).

"We launched investigations into these activities as soon as we became aware in mid-August," OpenAI said.

Services Australia and the Victorian Department of Health were informed of the incidents on 10 September, while BOCSAR was notified on 18 September.

The incident involving AIHW did not meet its disclosure thresholds, OpenAI said, but it noted that it notified the institute on 24 September to share findings and offer a briefing.

What is OpenAI doing now?

OpenAI said it has started working closely with Australian government agencies to share what it has learned to date.

"If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge," it said.

It is also committing dedicated support to the affected agencies to help them understand the incident and assess its impact, according to OpenAI.

It will establish a taskforce drawing on independent Australian expertise to develop practical policy recommendations for managing risks from increasingly capable AI agents.

"The taskforce's recommendations will inform OpenAI's approach and support the Australian governments' work on AI safety and cybersecurity," it said.

OpenAI said it is also supporting Australian governments and industry through credits from its $1 billion Daybreak for Frontline Defenders fund and technical assistance to strengthen cyber defences across critical infrastructure and other sensitive environments.

Daybreak for Frontline Defenders is a new global initiative to help frontline defenders use frontier AI cyber capabilities to protect essential services.

"One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional," it said.

Meanwhile, OpenAI chief strategy officer Jason Kwon will travel to Australia to appear before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October.

"He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward," OpenAI said.

'New kind of cyber incident'

The unauthorised access by OpenAI's AI agents to Australian government websites has been described as a world first. The AI firm later admitted that its agents had also attempted to interact with the websites of several US government agencies.

"This is a new kind of cyber incident which represents an emerging global challenge," OpenAI said in its blog post.

Speaking at a press conference in Adelaide on Tuesday, Albanese acknowledged OpenAI's efforts.

"OpenAI have been very constructive and open in engaging in that process and I welcome that, as have some of the other, Anthropic as well have been constructive in the engagement that's taking place," he said.

The prime minister added that the incidents, including those in the United States, highlight the risks posed by AI agents.

"So we need to work this through. We see this as an opportunity, but we want to seize the benefit whilst mitigating the risks," he said.

"That's the task that we have going forward. And I welcome the engagement with OpenAI."

LATEST NEWS