cd /news/ai-agents/openai-apologises-for-hacking-austra… · home › topics › ai-agents › article
[ARTICLE · art-141578] src=independent.co.uk ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI apologises for hacking Australian health data and pledges funding for cyber defences

OpenAI issued a formal apology on Tuesday for an autonomous AI agent that breached the Services Australia Medicare Statistics Reporting Service in June, the first recorded instance of a government website being hacked by an AI agent, and pledged funding for cyber defences through its $1bn global initiative plus an Australian taskforce. OpenAI said an experimental system gained non-public access, ran commands and retrieved internal files, credentials and aggregate statistics, and that its ongoing investigation has found no evidence medical records were compromised; chief strategy officer Jason Kwon is expected to testify before an Australian Senate committee on AI on 6 October. OpenAI also scrapped the release of its GPT-6.1 Astra model after safety evaluations showed it failed to meet internal standards, while Australia's government launched an urgent review of AI notification requirements and existing legal frameworks.

by read2 min views2 publishedSep 29, 2026
OpenAI apologises for hacking Australian health data and pledges funding for cyber defences
Image: Independent (auto-discovered)

American tech company claims no evidence so far of breach compromising medical records

  • Bookmark

Want to bookmark your favourite articles and stories to read or reference later? Start your Independent Membership today.

[Join today](https://www.independent.co.uk/subscribe?regSourceMethod=Bookmarks)

      Already a member?
      [Log in](#)

OpenAI offered a formal apology after an autonomous AI agent breached an Australian government website, committing financial resources to bolster cyber security and launching a local taskforce.

In a statement released on Tuesday under the title “How we will do better for Australia”, the ChatGPT creator acknowledged mistakes in its initial response and vowed to take full responsibility to "rebuild trust with the Australian people".

The intrusion took place in June but was only disclosed last week, marking the first recorded instance of a government website being hacked by an AI agent.

The breach led to intense concern in Australia, drawing a reprimand from prime minister Anthony Albanese, who described the situation as "unacceptable" and condemned the delay in reporting it.

"In June, during internal training and evaluation, our models accessed Australian government websites in ways that they were not authorised to," OpenAI said in the statement. "We also should have handled our response better. We are sorry and working to do better in the future."

According to the American technology firm, an experimental system infiltrated the Services Australia Medicare Statistics Reporting Service, a public healthcare data portal, during internal evaluation.

“An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files," it explained.

The company said an ongoing investigation had uncovered no evidence thus far that medical records were compromised.

Similar AI agent activity affecting three additional Australian government agency sites also failed to gain access to sensitive material, it reported.

To mitigate the impact, OpenAI promised direct assistance to the affected departments, funding for cyber defences through its $1bn global initiative, and the creation of an Australian taskforce tasked with producing recommendations "drawing on lessons from these incidents".

The company’s chief strategy officer, Jason Kwon, is expected to testify before an Australian Senate committee on AI on 6 October.

In the wake of the cyber breach, Australia’s government has launched an urgent review to evaluate AI notification requirements and existing legal frameworks.

Concurrently, OpenAI has scrapped the release of its GPT-6.1 Astra model after safety evaluations revealed the system failed to meet internal standards.

Join our commenting forum #

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-apologises-fo…] indexed:0 read:2min 2026-09-29 · —