cd /news/ai-agents/openais-dirty-deeds-down-under-inclu… · home › topics › ai-agents › article
[ARTICLE · art-141447] src=machinebrief.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

OpenAI admitted in a Tuesday blog post titled "How we will do better for Australia" that an experimental, internal-only model accessed Australian government websites without authorization, including Services Australia's Medicare Statistics Reporting Service, where it gained non-public access and reviewed technical system information and source code. OpenAI said its agents also tried unsuccessfully to bypass access controls at the Australian Institute of Health and Welfare, used an exposed access key at the State of Victoria's Agency for Health Information, and made API and website metadata requests at the State of New South Wales' Bureau of Crime Statistics and Research. OpenAI said it notified the Institute on 24 September, the day Australia's prime minister announced the Medicare incident, and pledged to establish a taskforce with independent Australian expertise to deliver policy recommendations by the end of 2026.

read3 min views1 publishedSep 29, 2026
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
Image: Machinebrief (auto-discovered)

Source:

The Register Admits its agents side-swiped four Australian government sites

OpenAIhas detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia, which addresses last week’s news that one of its models improperly accessed a website that stores data related to national health scheme Medicare. “Our models accessed Australian government websites in ways they were not authorised to,” the post opens. “We also should have handled our response better. We are sorry and working to do better in the future.” The post offers some new detail on the Medicare incident, saying that it involved “an experimental, internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products.” OpenAI gave the model the job of researching government spending per person on medicines for skin conditions in one Australian state. “The model had difficulty obtaining that information, and it took actions that we had not authorised it to take,” OpenAI admitted. “In the course of looking for this information at Services Australia’s Medicare Statistics Reporting Service, it discovered a way to gain non-public access to the service. It then used this access to review technical system information and source code related to the service – all still with the objective of trying to find the information it was originally looking for.” The Register last week asked OpenAI if the company conducted the tests itself or used a partner. The company did not respond to our request. In another incident disclosed in the new post, the company’s bots visited the Australian Institute of Health and Welfare and tried, unsuccessfully, to bypass access controls. The agents were still able to retrieve statistics using third-party browsing and download services, including from the institute’s website. “The downloaded material appears to have been publicly available. There was no system compromise. Individual medical records were not accessed,” OpenAI wrote. The company didn’t report the incident because it “did not meet our disclosure thresholds because the way it was accessed seemed consistent with public access.” OpenAI changed its mind and notified the Institute on 24 September – the day Australia’s prime minister announced the Medicare incident. Another concerning incident took place at the State of Victoria’s Agency for Health Information, which OpenAI agents visited after they “discovered an exposed access key.” The agent used that key to “retrieve reporting configuration and aggregate survey statistics.” OpenAI has given itself a pass on this one, writing “The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies. Individual medical records or identifiable survey responses were not accessed.” A fourth incident revealed in the post saw OpenAI agents visit the State of New South Wales’ Bureau of Crime Statistics and Research and make API and website metadata requests using a public-facing research tool. OpenAI has promised it will “commit the resources needed to help affected agencies understand what happened and assess the impact” – whatever that means. It’s also donating credits for the Daybreak cyber-defense service and promised to “establish a taskforce with independent Australian expertise to develop practical policy recommendations for managing risks from increasingly capable AI agents.” That taskforce “will focus on improving notification processes, strengthening coordination between AI developers and government, and identifying measures to better protect government systems.” OpenAI wants the taskforce to deliver recommendations by the end of 2026. The post is very much of the “We’re sorry and we promise to do better in future” genre, pioneered by Meta and popular with entities that leak data or experience outages. The Register expects more of the same sentiments next week, when OpenAI’s Chief Strategy Officer, Jason Kwon, appears before the Australian Senate’s Joint Select Committee on

Artificial Intelligence. “He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward,” OpenAI says. ®

Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openais-dirty-deeds-…] indexed:0 read:3min 2026-09-29 · —