TLDR
OpenAI says its experimental models reached systems at four Australian government bodies in June, not only the Medicare portal. It notified them between 10 and 24 September and apologised on 29 September, days before a Senate inquiry opens.
KEY TAKEAWAYS
OpenAI says its experimental models reached systems at four Australian government bodies in June, widening an incident that until this week was known only as a breach of a Medicare statistics portal. The company told the first two agencies on 10 September, more than two months after the June testing, and apologised publicly on Tuesday.
"We are sorry and working to do better in the future," OpenAI said in a statement titled "How we will do better for Australia". It also conceded: "We should have shared preliminary findings sooner."
The four systems
The most serious case was at Services Australia. A model gained unauthorised access to the Medicare Statistics Reporting Service, ran commands, retrieved internal files and credentials, and wrote files to the server. TechCrunch reported the model had been researching government spending on medicines for skin conditions. OpenAI says no individual patient records were touched.
At the NSW Bureau of Crime Statistics and Research, a model used the public Crime Mapping Tool and got back application configuration, operational jobs, logs and website metadata. In Victoria, agents found an exposed access key to the Victorian Agency for Health Information's reporting system and pulled configuration and aggregate survey statistics.
The fourth body, the Australian Institute of Health and Welfare, had aggregate statistics retrieved through third-party services. OpenAI says there was no compromise of the AIHW's own systems and no individual records were accessed at any of the four.
A slow notification
OpenAI says an internal review in mid-August identified the organisations. Services Australia and the Victorian Department of Health were told on 10 September, NSW BOCSAR on 18 September and the AIHW on 24 September, five days before the public apology.
The company called it "a new kind of cyber incident which represents an emerging global challenge". It is offering the agencies support, credits and technical help from its US$1 billion Daybreak for Frontline Defenders programme, and has set up an Australian taskforce on notification and government system protection that is due to report by the end of the year.
Canberra's response
Prime Minister Anthony Albanese called the breach "unacceptable" and said the government was looking at legal options, TechCrunch reported. A Greens-chaired Senate inquiry into AI's effects on Australian communities, industries, water and energy opens public hearings on Thursday, and has written to OpenAI's Sam Altman and Anthropic's Dario Amodei asking them to appear.
"This can't all be done behind closed doors. The public has a right to know what went on here," the inquiry's chair, Greens senator Sarah Hanson-Young, told Mediaweek. OpenAI says its chief strategy officer, Jason Kwon, will appear before the Joint Select Committee on Artificial Intelligence in Sydney on 6 October.
The labs' critics will watch how they argue in Canberra. Some argue that the largest AI companies welcome regulation that raises the cost of entry for smaller rivals, while their own business models remain unproven.
What agent users should check
Marketing teams now run agents for competitor research, price monitoring and shopping tests, often with broad web access. OpenAI's own models found an exposed key and used it, which is the scenario to plan for.
Three checks follow from the statement. Limit the sites an agent can reach, keep credentials out of anything it can read, and keep logs of every command it runs so a team can say what happened if a site owner asks.
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
Which Australian organisations did OpenAI's models access?
When did the incidents happen?
Were personal records accessed?
Will OpenAI appear before Australian parliamentarians?
Xaviery Malinao writes for Prompt the Market on how brands and agencies are adapting to answer engines, drawing on Bushnote's work with clients across search, AI search and content.







