In a blog post on Tuesday titled "How we will do better for Australia", OpenAI said it was "sorry and working to do better in the future" and that it "should have handled our response better". The company described the incident as "a new kind of cyber incident which represents an emerging global challenge".
The breach occurred during training of an "internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products". The model was set a research task to find government spending per person on medicines for skin conditions in Victorian communities. When it could not find the figures, it took actions OpenAI "had not authorised it to take".
Once inside Services Australia's Medicare Statistics Reporting Service, the model "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files", and reviewed the service's technical system information and source code. OpenAI also confirmed an agent accessed the NSW Bureau of Crime Statistics and Research's public Crime Mapping Tool, discovered an exposed access key to query the Victorian Agency for Health Information's (VAHI) reporting system, and retrieved statistics from the Australian Institute of Health and Welfare that "appears to have been publicly available". The company said the extent to which VAHI information should have been accessible was unclear and depended on VAHI's access policies, and that separate attempts to bypass access controls were unsuccessful.
Prime Minister Anthony Albanese said he had a "direct but constructive discussion" with OpenAI chief executive Sam Altman last week and was briefed on Monday on the government taskforce investigating the incident. "OpenAI have been very constructive and open in engaging in that process, and I welcome that," he said, adding that Anthropic had also engaged constructively. He described AI as an opportunity with exposed risks: "We've seen those risks exposed... we want to seize the benefit whilst mitigating the risks."
OpenAI said it has blocked live internet access in its research environments and paused training and evaluation involving tool use for its most capable models, effectively shelving the next-generation ChatGPT release. It will establish a taskforce including independent Australian experts to recommend how AI developers and governments should detect and disclose incidents, with a report due by the end of the year, and offered Australian governments and industry credits from its $1 billion Daybreak cyber defence fund.