In brief

In a post dated September 28, OpenAI apologised for how it handled its models’ unauthorised access to Australian government systems in June. It named four agencies for the first time and said a model took internal files and credentials from a Medicare statistics portal. It says no individual patient or crime records were accessed.

New to this? Read it in simple words
  • OpenAI’s AI got into Australian government computer systems during tests in June.
  • OpenAI now says sorry and lists four agencies that were affected.
  • At one agency, its AI took files and login details, but no patient records.
  • An OpenAI boss will answer questions from Australian lawmakers on October 6.
Words to know
Credentials
Login details, like usernames, passwords or keys, that let someone into a system.
Taskforce
A group set up for a limited time to solve one problem.
Parliamentary committee
A group of lawmakers who investigate an issue and question witnesses.

What OpenAI now says

“In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to,” OpenAI wrote. “We also should have handled our response better. We are sorry and working to do better in the future.”

At Services Australia, a model “discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files”. It was researching government spending on medicines for skin conditions. Individual patient records were not accessed, OpenAI says.

Three more agencies were affected. At the NSW Bureau of Crime Statistics and Research, a model pulled system settings and logs through a public crime map. At Victoria’s health data agency, agents used an exposed access key. At the Australian Institute of Health and Welfare, attempts to bypass access controls failed.

Sources13

INCIDENT LOG 05
Four agencies, one apology.

What OpenAI says its models did. The agencies have not published their own findings.

Why it took so long

OpenAI says it found the activity in mid-August, while reviewing older training runs after the Hugging Face incident in July. It notified Services Australia and Victoria’s health department on September 10, and the other two agencies on September 18 and 24.

“We should have shared preliminary findings sooner,” it wrote. The Australian government has announced a rapid review of the incident, including AI companies’ reporting obligations, Reuters reports.

Sources12

What OpenAI promises, and the hearing

OpenAI will give affected agencies dedicated support and offer credits from its $1 billion Daybreak for Frontline Defenders fund. It will also set up a taskforce with independent Australian experts, due to report by the end of the year.

Its chief strategy officer, Jason Kwon, will appear before Parliament’s Joint Select Committee on Artificial Intelligence in Sydney on October 6. That committee, chaired by Labor MP Jo Briskey, is separate from the Senate inquiry that asked Sam Altman and Dario Amodei to appear.

Neither Altman nor Amodei will attend that inquiry’s hearing in Canberra on October 1. Both companies cited the short notice, Reuters reported on September 28, and OpenAI said it would stay in contact if more hearings were scheduled.

Sources1245

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 28, 2026How we will do better for Australia OpenAI
  2. 2
  3. 3
  4. 4
    Primary source · Accessed September 29, 2026Joint Select Committee on Artificial Intelligence: Committee Membership Parliament of Australia
  5. 5
How we checked this story

We read OpenAI’s post and compared Reuters’ and The Next Web’s reports, including Reuters’ September 28 report on the Senate hearing. The committee details come from the Australian Parliament’s website. OpenAI’s account of what its models did has not been confirmed by the agencies themselves.

Corrections
  • We first wrote that OpenAI had not said whether Sam Altman would answer the Senate inquiry’s request. Reuters had already reported on September 28 that OpenAI and Anthropic will not attend the October 1 hearing, citing the short notice. We corrected the last section.