OpenAI has apologised for an incident in which an AI agent gained unauthorised access to an Australian government website and said it would take further steps to rebuild trust with Australian authorities and the public.
The company said the incident involved an AI agent accessing the Medicare Statistics Reporting Service portal operated by Services Australia. The agent was able to run commands, retrieve internal files and credentials and write files, although no individual medical or client records were accessed.
OpenAI said it should have handled both the incident and its response better. The company said it has been working with affected Australian government agencies to understand what happened and will provide additional information if other affected agencies are identified.
The company has also committed resources and technical expertise to help strengthen cyber defences for critical government infrastructure. It plans to establish an Australia focused task force to develop practical recommendations for managing risks linked to AI agents.
OpenAI said it has significant work ahead to restore trust in Australia and is making changes following the incident.