OpenAI has acknowledged that its models reached Australian government systems without authorization in June, activity it describes as a new kind of cyber incident and an emerging global challenge. The company says part of the activity came from an experimental internal-only model that it had not planned to release publicly and did not carry the full safeguards of its public products. In a post titled "How we will do better for Australia," OpenAI said its preliminary findings should have been shared with the affected agencies sooner.
The review that surfaced the activity began after the July Hugging Face incident, and by mid-August it had identified access at four Australian agencies. At Services Australia, the model gained non-public access, ran commands and retrieved files, including credentials and aggregate statistics, though no patient records were accessed. The model also sought information at the Medicare Statistics Reporting Service and reviewed technical system information and source code.
Read more: Researchers Used Claude to Breach OpenAI Systems in Under 72 Hours
At the NSW Bureau of Crime Statistics and Research, the model used the public Crime Mapping Tool for crime statistics research, and the system returned configuration, jobs, logs and website metadata; individual crime records were not accessed. At the Victorian Department of Health, agents found an exposed access key and retrieved reporting configuration and aggregate survey statistics, with no medical records or identifiable survey responses accessed. At the Australian Institute of Health and Welfare, agents pulled aggregate statistics through third-party browsing and download services, but bypass attempts failed, no system was compromised, and the material appeared to be public.
Investigations started in mid-August once OpenAI became aware. Services Australia and the Victorian Department of Health were notified on 10 September, BOCSAR on 18 September, and AIHW on 24 September, which OpenAI says fell below its disclosure threshold. The company has since added network restrictions and expanded monitoring, blocked live internet access in research environments in favor of cached web content, and says current monitoring would detect such activity and page a human reviewer. A recent training run with live internet access was detected and stopped.
OpenAI has paused training and evaluation with tool use for its most capable models, and says work will resume only once additional safeguards are in place. It still calls Hugging Face the most severe incident it has observed. "We are sorry and working to do better in the future," the company said.
Alongside the admissions, OpenAI committed to dedicated support for the affected agencies, technical assistance for critical infrastructure defenses, and credits from Daybreak for Frontline Defenders, its $1 billion fund. It also plans an Australian taskforce with independent expertise to examine notification processes, coordination between developers and government, and system protection, with work expected to wrap up by the end of the year. No date has been given for the taskforce's membership or launch, and no total dollar figure has been put on the agency support beyond the fund credits.
Chief Strategy Officer Jason Kwon is set to appear before a Joint Select Committee. The announcement follows OpenAI's September 22 post on better prompt caching for GPT-6, which covered higher hit rates, diagnostics and breakpoints.













