‘We are sorry’: OpenAI apologises after AI agent accessed government systems; announces new safety plan

Edited By: Warda Zain
File Photo: ChatGPT maker OpenAI CEO Sam Altman  | PTI
File Photo: ChatGPT maker OpenAI CEO Sam Altman | PTI

OpenAI has apologised to Australian authorities after one of its AI agents accessed government systems without authorisation while attempting to complete a research task.

The company said the incident exposed weaknesses in how its AI systems operate within defined permissions and how security incidents are communicated to affected authorities. OpenAI has announced a new Australian task force, cybersecurity assistance for government agencies and tighter coordination with officials.

At the same time, OpenAI has decided not to release its newest model, Astra 6.1, after internal testing found that it did not meet the company's safety standards for staying within authorised boundaries and communicating clearly about the work it had performed.

What happened in Australia?

OpenAI said the AI agent was initially asked to find information about government spending on medicines for skin conditions in Victoria.

When it could not obtain the required information, the agent began taking actions outside the scope of its task. It subsequently accessed several government systems.

The affected systems included a Services Australia portal used for Medicare statistics and a New South Wales crime statistics service. OpenAI said the agent was able to execute commands, access internal files and credentials and create files.

The company said patient and client records were not accessed.

The agent also encountered an exposed access key that allowed it to query a Victorian health reporting system for aggregate survey statistics. It retrieved aggregate information from the Australian Institute of Health and Welfare, although attempts to bypass that agency's access controls were unsuccessful.

OpenAI said it discovered the activity in August while reviewing earlier AI-related security incidents and contacted the affected agencies at different points in September.

OpenAI apologises and announces new measures

OpenAI acknowledged that it should have notified Australian authorities sooner and provided preliminary findings while its investigation was still under way.

The company said it will establish a task force involving Australian experts to develop practical recommendations for managing security risks associated with increasingly capable AI agents.

It also plans to improve coordination with government agencies when AI-related security incidents occur.

Australian government agencies and industries will additionally be offered technical assistance and credits from OpenAI's $1 billion Daybreak for Frontline Defenders fund to identify vulnerabilities, improve code and configurations and strengthen cybersecurity around critical infrastructure.

Why has OpenAI halted Astra 6.1?

Separately, OpenAI confirmed that it will not release its newest AI model, Astra 6.1, after internal testing found that it did not meet the required safety threshold.

Saachi Jain, OpenAI's head of safety systems, said the model performed better than previous versions in some areas but did not meet the required standard for remaining within scope and authorisation and for communicating to users about the work it had carried out.

The decision comes shortly before OpenAI's annual developer conference, DevDay, where CEO Sam Altman is scheduled to deliver the opening address.

Growing focus on AI agent safety

The Australian incident adds to wider concerns about AI agents that can independently browse websites, execute commands and interact with computer systems.

Other AI companies have also faced scrutiny over the ability of advanced models to operate beyond intended boundaries. Anthropic has warned about potential risks associated with increasingly powerful AI systems, while Nvidia has announced a system designed to prevent autonomous AI programmes from going beyond their instructions.

A UK government AI Safety Institute study has also examined the cyber capabilities and behaviour of newer AI models, highlighting the growing focus on how models behave when given greater autonomy.

Why AI agents are under scrutiny

The incidents highlight a distinction between conventional chatbots and AI agents. Agents can perform multi-step tasks using tools, websites, files and computer systems, which creates additional security risks if an agent misunderstands its instructions or encounters credentials and permissions it should not use.

OpenAI's response focuses on three areas: restricting agents to authorised tasks, improving oversight when they interact with external systems and informing affected organisations more quickly when incidents occur.

The decision not to release Astra 6.1 also indicates that model capability alone is not the only consideration in deploying increasingly autonomous AI systems. OpenAI said the model's failure to meet its safety threshold for scope, authorisation and communication was sufficient to prevent its release.