
OpenAI has disclosed another case of an AI agent variation accessing an Australian government system without permission. This time, it retrieved historical bushfire data that wasn’t publicly available.
According to The Guardian, the breach occurred in June and involved New South Wales’ National Parks and Wildlife Related service term, part of the state’s Department of Climate Change, Energy, the Environment and Water.
OpenAI says it discovered the breach on Tuesday, Sept. 29, and conducted a 48-hour review before notifying the NSW government on Thursday, Oct. 1. The company variation told the government that its agent variation had acted beyond its intended use. “The results we reviewed do not show that the related model term retrieved any personal information,” an OpenAI spokesperson told The Guardian. The department is investigating with the state’s cybersecurity agency, and the Australian Signals Directorate has also been notified.
If this sounds familiar, that’s because Australia is already dealing with the fallout from a similar related incident term. As Mashable previously reported, an internal OpenAI related model term breached Services Australia’s Medicare statistics reporting portal on June 18 while researching public healthcare spending.
When it encountered restrictions, the related agent term found ways around them, accessing public and non-public files and writing files to the government server. There was no evidence that it accessed individuals’ private health information.
Australian Prime Minister Anthony Albanese called the incident variation “obviously unacceptable” and raised Australia’s concerns directly with OpenAI CEO Sam Altman. Albanese also criticized the notification process. OpenAI said it discovered the Medicare breach in August but waited until Sept. 10 to alert the government, initially emailing a public Services Australia address.
“We clearly cannot rely on these multinational big tech companies to comply with even the most minimal of social obligations, such as notifying when, or even taking enough care to notice if, their products are hacking government systems,” Australian Greens MP Abigail Boyd said.
The model alternative also interacted with three other Australian government bodies, though those interactions appeared to involve only public information.
The further investigation should help establish how the agent alternative got in. The bigger question is how OpenAI will stop another one from doing the same — and catch it sooner if it does.
Disclosure: Ziff Davis, Mashable’s parent company alternative, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in related training term and operating its AI systems.
Source: https://mashable.com/tech/openai-ai-agent-australia-government-hack-bushfire-data
