OpenAI disclosed on 28 September that its models accessed Australian government systems without authorisation during internal training runs in June, and that it did not discover this until mid-August, while reviewing activity following a separate earlier incident.
Four bodies are named. At Services Australia’s Medicare Statistics Reporting Service, a model retrieved internal files, credentials and aggregate statistics. At the NSW Bureau of Crime Statistics and Research, a model working through the public Crime Mapping Tool was handed API credentials in a response and used them to pull application configuration, operational logs and metadata. At the Victorian Department of Health, agents found an exposed access key and queried reporting systems for aggregate survey statistics. At the Australian Institute of Health and Welfare, they retrieved only publicly available figures. OpenAI states that in each case individual patient, client or crime records were not accessed.
In three of the four cases, what the models used was a credential the agency had left exposed — which makes this a story about the security of public systems as much as about model behaviour.
OpenAI’s commitments are dedicated support for the affected agencies, funding through its $1bn Daybreak for Frontline Defenders fund, an Australian taskforce to be completed by year-end, and an appearance by its chief strategy officer before Parliament on 6 October. Its own account is here.
