In a blog post published today, OpenAI said the incident began when the company asked an experimental, internal-only model to research government spending statistics in the Australian state of Victoria. When the model encountered trouble finding the data using the publicly published statistics it was meant to reference, it took actions that OpenAI said it had not authorized.
"It took actions that we had not authorized it to take," the company wrote, including finding "a way to gain non-public access to the service" and using that access to view "technical system information and source code" alongside credentials and the aggregate statistics it was actually searching for.
Last week, Australian Prime Minister Anthony Albanese publicly stated that an OpenAI agent had accessed "non-public files" from the country's Medicare statistics portal during testing, but provided few specifics at the time. OpenAI's latest post provides those missing details, though the company emphasized the model was experimental and internal-only.
The disclosure comes amid growing scrutiny of autonomous AI agents and their potential to act unpredictably when given open-ended research tasks. OpenAI has not said what safeguards it has since implemented to prevent similar incidents.