Release details
Release type
Related ministers and contacts
The Hon Richard Marles MP
Deputy Prime Minister
Minister for Defence
Media contact
Senator The Hon Katy Gallagher
Minister for Finance
Minister for Women
Minister for the Public Service
Minister for Government Services
Release content
24 September 2026
SUBJECT/S: OpenAI incident
RICHARD MARLES, ACTING PRIME MINISTER: Welcome everyone here this morning, it is good to be here before you and to be here with Katy Gallagher, who in this context, is the Minister for Government Services. In June of this year, a model, an AI model, that was undergoing training by OpenAI, interacted with four public websites in Australia. They were the Australian Institute of Health and Welfare, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research, and the Medicare Statistics Reporting Service Portal of Services Australia. In relation to the first three, those interactions were entirely normal and public information was accessed. But in relation to the Medicare Statistics Portal of Services Australia, the agent of the AI model, on first requesting the information, and that information being denied, engaged in what's described as misaligned behaviour and engaged in unauthorised access of that portal in order to gain the information. This is a very serious incident, as the Prime Minister has made clear overnight. It is utterly unacceptable. And again, as the Prime Minister made clear, he has expressed this to Sam Altman, the CEO of OpenAI. The government is taking this very seriously. That said, it is important to reassure the Australian public that the impact of this incident is relatively minor. We are talking about aggregated medical statistics. No individual's medical data was accessed here. The system itself has not been in any way compromised. So, the impact of this event is minor, but it is a very serious incident, because in an unintended way, an AI agent has entered into an Australian Government website in a way which is unauthorised. In response to this, we are establishing a task force which is being led by the Department of Prime Minister and Cabinet that will involve the Australian Signals Directorate, the AI Safety Institute, the Office of AI and other government agencies. This will be a task force that will be rapid. It will look at this incident thoroughly, but it will also examine our posture in respect of emerging AI cyber threats. It will look at the security of government networks. It will look at the legal arrangements that we have in place in respect of an incident of this kind. The terms of reference of this task force are being made public now. I want to say and acknowledge that OpenAI have been working with us very cooperatively here. They have clearly notified us of this and engagement with them has been critical to understanding what has occurred. We are grateful for that. That said, what has occurred here is obviously completely unacceptable. And that was made clear in the plainest terms by the Prime Minister in speaking with the CEO of OpenAI over the course of last night. All of this I think we can take as a warning in relation to the development of AI itself. It is so important that this technology, which represents such an enormous opportunity for humanity, is nevertheless being developed in a way where the guardrails, the safeguards are well ahead of the capability itself. And that's why the Prime Minister, along with other world leaders in New York over the course of this week, has put out a call to ensure that AI is developed in a safe way with guardrails in place. That is very clearly the position of the Australian government as articulated by the Prime Minister. For what it's worth, it's also the position of the CEOs of these tech companies. Over the course of last night, Dario Amodei, Sam Altman and others appeared at the UN to express exactly the same sentiment. We saw Dario Amodei, the CEO of Anthropic's, essay in the last couple of weeks going exactly to this point. AI is a transformational technology. It offers so much benefit for humanity, but it comes with danger. And it is really important that the safeguards and the guardrails are well ahead of the capability itself. And that is very much the position of the Australian government and the way in which we will be engaging with this technology and seeking to regulate and manage it in an Australian context.
KATY GALLAGHER, MINISTER FOR GOVERNMENT SERVICES: Thanks, Richard. So, I'm here as Minister for Government Services, which the agency Services Australia sits under. I thought it might be useful if I can take you through some of the Services Australia information I can give you right now. That's as up to date as it can be. So, on 10 September, Services Australia was notified by OpenAI that an AI agent had accessed infrastructure behind the public-facing Medicare Statistics Reporting Service portal, which hosts that publicly available aggregate Medicare and Pharmaceutical Benefits Scheme statistical data that the DPM just mentioned. The agent was undertaking a task by OpenAI to conduct internet-based research into public medicine spending as part of internal capability evaluation. So, on the website that it accessed, the Medicare Statistics Reporting Service Portal is a standalone website, it's public-facing and it is not in any way related to Medicare in terms of claims, payments, processing, individual information. So, it's a completely different system and the two shouldn't be conflated. It's a public website. It's most often used by researchers and academics who get that aggregated data about benefit statistics, prescribing statistics, to use in their own research. Now, the notification from OpenAI went to an email address called publicdisclosures@servicesaustralia.gov.au, which is an email address that is used by researchers usually and academics and others to notify Services Australia if they think a vulnerability exists in some of Services Australia's systems. So, it went to that email address. By 15 September, once Services Australia had analysed the information in the email and made some checks, they notified the incident to ASD. Following that, I was advised around the 17th of September, and undertook, and sought further information from the initial information. And then over the course of the weekend, that was late last week, I had a number of discussions both with the DPM and the Minister for Home Affairs and Services Australia and ASD. So, quite a lot of work over that weekend to try and get to the bottom of what had happened here. So, the first technical exchange between OpenAI and Services Australia happened on Tuesday this week. That was when Services Australia was able to ask specific questions and ask for, you know, the tech, the logs essentially and some of the data that OpenAI had. There are going to be subsequent meetings of those, they haven't concluded. Now, Services Australia have a forensic investigation that's underway and they will provide a final report to me. I've also asked whether the $160 million we had in the last budget, which was to do a cyber uplift of Services Australia's essential infrastructure, can or should be accelerated. And also, that legacy public-facing websites, I’ve asked that the information there be moved to data.gov.au, or put on alternate existing secure platforms, or that they be decommissioned. This is a legacy system, it dates back decades, it's been used in the same way. But the data is now being provided, the data that was on that website is being transferred to data.gov.au. It is public data. There's no concerns with that. And that portal is no longer active.
MARLES: Questions?
JOURNALIST: How can you describe OpenAI as cooperative when all the reports seem to be that they've known about this for three months? And only decided to raise it with you guys in the last couple of weeks?
MARLES: Well, so let's go through the timeline. This incident occurred in June as they were training their model. There were literally millions of contacts that that model engaged in. We are advised by OpenAI that they became aware in August of the incident which involved an unauthorised access to an Australian website. They first notified us in the middle of September, on the 10th of September through to Services Australia and as Katy has said, Ministers became aware of this at the end of last week and we're now in the process of having the first technical interaction with OpenAI on Tuesday of this week. The point I'd simply make is that they are very cooperative in terms of the engagement that we are having with them now. It matters to have a relationship with OpenAI so that we can have that cooperation. We are learning a lot from that cooperation. So, I'm just acknowledging that. But I'm also acknowledging that this is a situation which is fundamentally unacceptable. And the principal message that was given by the Prime Minister to Sam Altman over the course of last night in New York was that this is a deeply unacceptable situation and the Australian government is extremely concerned about it. The establishment of the task force, the reason we are taking this so seriously is to thoroughly investigate this and to understand everything we can about it, including whether laws have been broken in the context of this.
JOURNALIST: How can you explain the delay in notification? Why did this not happen in August when it was discovered? And to that point, is there a way that the Australian government can force these foreign owned AI companies to notify as soon as the breach occurs and through more official channels?
MARLES: OK, so we have had an agency in respect of this since the 10th of September. We, the Australian government in the broader sense, and Katy walk through the timeline in relation to that. In terms of government Ministers, we've literally known about this for less than a week. And in terms of our actions, we have wanted to very carefully understand the information that we have at hand here. Making this public has its own consequences. We needed to do it with a certain amount of information at hand in making this public. And to be clear, the investigations are still ongoing, so we don't know everything yet in relation to this. And that's part of the task force and the work that we continue to do. But we really wanted to firstly assure ourselves that the impact of the specific incident was, as I had said, relatively minor. And we do want to be able to reassure Australians about that. But the incident itself is obviously very serious. It's very serious that we've got an AI agent having gained unauthorised access into an Australian website. Now, the moment that we felt that we were in a position to have that information at hand and to responsibly inform the Australian public, we have, in the course of last night and today, so that's our actions. In respect to OpenAI, we have expressed our concern to OpenAI about the amount of time it took for the Australian government to be made aware of this. I want to make that really clear as well. And that was part of the concern that the Prime Minister raised with OpenAI in his conversation with Sam Altman overnight. Again, as we work with OpenAI and we work with other frontier companies, a key part of that engagement is how we can be notified as quickly as possible.
JOURNALIST: Is what occurred illegal? And second to that, as this has been mentioned, this is a multinational company. Huge salaries for some of his senior employees. They have government relations people. Is it good enough to send it to a generic email address and not follow up in person?
MARLES: Well, I think in terms of the latter question, it's not good enough that that's how we first became notified of it. And I reiterate one of the points that was made very clear by the Prime Minister in his conversation with Sam Altman was our displeasure at the time that it has taken for the government to be properly notified about this. Now that we have been, we are wanting to work as closely as we can with OpenAI to properly understand everything that's occurred here. And they are being very cooperative. And I do want to acknowledge that. And it's important to acknowledge that. In respect of the legality, that is a very good question. And that is part of what the task force will seek to inquire and interrogate. This is an unintended access, that's clear. But it definitely does raise questions about whether the law has been broken in respect of this. And obviously we will investigate all of that, what the consequences are if there has been a breach of law, but also part of the task force is to assess whether or not the legal regime we have in place is fit for purpose in a world where we have an emerging AI capability.
JOURNALIST: Has Sam Altman explained to the Prime Minister why he failed to mention this to you when he met with yourself at the start of the month?
MARLES: I'm not aware whether that specifically occurred in the conversation with Sam Altman last night, but as you say, I did meet with Sam Altman in person earlier this month, before the 10th of September, and it wasn't the subject of that meeting.
JOURNALIST: Would have you expected him to have brought it up?
MARLES: Well, look, I don't know the specifics of what Sam Altman knew at that moment in time. And I think we do need to acknowledge there's a lot of technicalities here in terms of the information at hand. I think the best way to answer that question is the way in which I answered it previously is what we would expect is that the government be notified in the most timely manner possible. And we have expressed our displeasure that did not occur in this instance.
JOURNALIST: Minister, just one view. It sounds a little bit terrifying isn’t it? It's just the start. Should the public be worried? Also Minister, just from our Canberra office, the University of Canberra researcher Samuel Spencer says that he shared research to your office back in April that order of the public service doesn’t believe its data was secure. Did your office ignore those warnings?
MARLES: Is your question is AI terrifying?
JOURNALIST: Yes. Ok, now, this website didn't have a lot of information, but what's next? Defence? A very secure national security group?
MARLES: So, let me speak firstly to the security of government systems and then I'll speak to AI more generally. We have a whole range of IT systems across government and the level of security is relative to the information that is being protected. In this instance, it's not particularly sensitive information. In fact, the information has now been made public and so the security in place there was not the most significant security, and that's reasonable. The analogy I would give here is that it was behind a fence, the agent climbed the fence. When we're talking about the data of Australian individuals within the Australian government system, to continue the analogy, that's that which sits inside a safe. And when you're talking about our national security, our most sensitive information that we have, it sits behind a fortress.
JOURNALIST: Unbroken?
MARLES: Well, I'm very confident about the way in which we manage our sensitive information. And again, to give you a sense of context in respect of that, it is being probed and there is attention in respect of our secure information constantly. And we are able to manage the security of our most secure information, which includes, you know, our most sensitive national security information. But it very much includes the personal data of Australian citizens that are held by the Australian government. So, I'm actually really confident about the security of that. We obviously live in a changing world, but I think again, the best way to answer that is the Australian Signals Directorate, which is the custodian of our cyber defences, our cyber security, is really one of the very best organisations in the world at what it does and is acknowledged as such. So, we are in as good a position as any country in the world in terms of managing the security of the information. I highlight that the information that we are talking about here was not particularly sensitive. It's in fact now being made public. It was not sitting behind a particularly high fence. This AI agent scaled the fence, but it did scale it. And the point is it was unintended. It wasn't asked to. That's our concern here. It did not behave in accordance with what, you know, the guidelines of that portal were doing. It asked a question. The information was not given, and rather than leaving it at that point, it scaled the fence. That is our concern here. I guess that leads into the second part of your question, or the first part, which is AI more generally. Look, AI is an incredible technology. It may be the most transformational technology that any of us here live through. It obviously affords enormous benefits for humanity, but it is so important that it is developed in the context of secure measures and guardrails, which is to say that all of these companies are developing guardrails and security measures, and they are putting a lot of attention to that. That work must lead the development of the capability itself, so that when the capability is developed, it is happening within a secure border. Now, we've seen incidents over the last few months where that has not occurred. That is what's led to Dario Amodei's essay a couple of weeks ago. The CEO of Anthropic is what led to the tech CEOs speaking to the UN last night on exactly the same topic. But most importantly, it's why our Prime Minister and our government has joined leaders around the world to call for this technology to be developed in the context of very secure guardrails and very secure safety measures. And that's how we need to proceed.
GALLAGHER: Yes, yes. So, as I that was a researcher who wrote about the government data catalogue, so not specifically about AI. My office met with him and I've responded to that letter. On the issue of government data more generally, we've got a legislation in place called the Data Accessibility and Transparency Act that's due to sunset in April next year. So, there's work underway about how we manage data, what data can be and should be released publicly and made available, and then what are the data sets that we will never release and we will never allow anyone to have access to, which goes to some of the critical systems that DPM talked about. And just to assure people again, in relation to this incident, at this stage, no personal information is subject to this incident. And it's a completely different system, a public-facing website, as opposed to one of those systems of government significance that Services Australia run. And of course the cyber protections associated with that are quite different too.
JOURNALIST: On the timeline that you've just given, the email from Services Australia arrived on the 10th, but the ASD wasn't notified until the 15th. Why did it take the agency 5 days to notify ASD?
GALLAGHER: So, that email address is looked at once a day. It's a general, you know, we have someone who goes and has a look through. It gets sometimes quite a number of notifications, sometimes many of them are hoaxes. So, the answer I've been provided by Services Australia is that they checked it on the 11th, they received the information on the 11th. I think there was a weekend in there as well. And through their own systems and checking, including going back and having a look at their technical data, it took a couple of days to verify that what they'd been alerted to in the email was legitimate. And it was at that point that they engaged ASD.
JOURNALIST: Should that inbox be more actively monitored?
GALLAGHER: Obviously, we're having a forensic investigation of all things related to this. Obviously, that is one of them. In the technical exchange that happened on Tuesday, it was made very clear by both ASD and Services Australia that this notification should not have gone to a kind of, you know, email address. It should have been escalated through ASD's channels or through the senior levels of Services Australia. And my understanding is OpenAI accepted that as well.
JOURNALIST: Minister, why did it take over a week since the ASD looked at this before the government decided that they felt the need to announce it more publicly? And, Minister Gallagher, you said this was a legacy system. How have we been allowed to be so vulnerable to these kinds of breaches? And can you say with any certainty whether there's been breaches from other AI agents across government.
MARLES: So, I understand the interest in the timeline, but if we take a step back, an email goes to, effectively a public email address within Services Australia and 14 days later, we are standing before you. In that period of time, this has been escalated through the Australian government to the highest level. Now, there is a lot of information which comes into inboxes. There's a lot of assessment that needs to be done in terms of understanding exactly what it is, in an emerging context, that is being spoken of here. There is consequence, and this is the important point, there is consequence in terms of us speaking publicly about this, but it is important for us to speak publicly in terms of public transparency. In being able to stand before the Australian people right now and to do so with a sense of confidence, not complete knowledge, but with a sense of confidence that the impact of this particular incident was minor, albeit it is a serious incident, is really important. We needed to make sure that we could stand here with confidence to give that assurance. To have gone public without all the facts at hand or without that level of confidence would, I think, have been reckless. And so we are trying to have a balance here of getting this information into the public domain as quickly as possible. And it has all happened within two weeks, within two weeks, but also to make sure that what we are putting into the public domain is enough of the picture that it can raise the seriousness of the issue, but it can also give people a sense of confidence that the impact of this has been relatively minor. The way we regard this is taking this incident as a salutary warning. I mean, this is a warning about the technology being developed without safeguards and without guardrails in place. And that is why we are taking it really seriously, establishing the task force, making sure that we understand this incident thoroughly. But what we need to do going forward and learning every lesson from it in a context where the impact of this particular incident was relatively minor.
GALLAGHER: Can I just go back, sorry, because you had a second part to that question. So, just to again reiterate that the technical briefing, which gave us a level of comfort about what this agent had been doing, was not provided until Tuesday. So, we are here on Thursday. To be able to come out with as much information as we could and as much assurance as we could about the type of activity as we understand it to be now. In relation to your question about the vulnerability of this system, it is a legacy system, you know, and it is being moved to data.gov.au so we won't be reactivating it, but there is protections associated with that, this is unprecedented activity. So, there are, you know, there are programs including to protect against bots and things that protected that website. But this is identified and in fact, OpenAI’s email to us was to identify a vulnerability that had been found in that system and the need to deal with that. So, there are systems in place. Obviously it's not a system of government significance, so it doesn't have the cyber protections that you would expect on that personally held information, but it did have protections in place. Unfortunately, this agent got around that.
JOURNALIST: Has OpenAI given your government assurances that there have been no other instances where its models have gained unauthorised access to Australian Government data?
GALLAGHER: Well, this is the incident that we're aware of and OpenAI have been very transparent with us in relation to this. Obviously, we've become aware of this because OpenAI have notified us of this particular incident. So, again, I think it is important to acknowledge that's what's occurred here with OpenAI. Look, part of what we will do with the task force is to examine not only this incident, but the way in which government systems have been interacting with external AI more generally.
JOURNALIST: (indistinct) seems to have written files from the internal server as well. Can you run us through what that was about and what kind of message does this send? You know, if an AI that wasn't explicitly told to hack into us did and was able to write files to the server, what message does this send to malicious actors out there in coming days before, you know, there are solutions from the task force.
GALLAGHER: I mean. Well, they're some of the issues that we've had to work through in the last 48 hours. You know, as the DPM says, going public with statements like this has consequences. So, you know, all of our systems are working to be, you know, as you would expect, to keep Australians safe. Look, that's really, you know, we've got the forensic investigation underway with Services Australia. We don't have all the information yet. We've got another technical briefing that will occur with OpenAI where, because Services Australia has sought additional information from OpenAI that wasn't able to be resolved on Tuesday. So, we will understand more of that as some of that discussion.
JOURNALIST: Is that to be around writing the files?
GALLAGHER: Yes, aspects around that, absolutely.
MARLES: And can I say that on this - the task force will obviously examine all of that and seek to understand this as thoroughly as we possibly can. And as Katy has said, there will be more engagement with OpenAI in respect of this. But I would really want to reassure Australians that in terms of the sensitive information that the government has about Australian citizens, but also our most sensitive national security information, that sits in a very secure domain in a context where it is receiving constant attention and probing, and it has maintained that security through until this day. Now, we don't. We're not sanguine about that. We seek to learn everything we can from this incident. We seek to be constantly improving in an emerging environment, but we are amongst the world's leaders in relation to the way in which we manage cyber security, and particularly of government systems, but also critical infrastructure within the private sector. ASD leads that work and Australians should take a great deal of confidence from that. Thank you.
ENDS