The breach occurred June 18, when an OpenAI agent accessed a database in Australia’s national health care system, Albanese said.
Australian Prime Minister Anthony Albanese expressed concern and disappointment over OpenAI’s breach of a national health department website, saying the company took too long to notify the government.
“It took the company way too long to inform the government what had occurred,” Albanese said Wednesday at a news conference on the sidelines of the United Nations General Assembly.
The breach occurred June 18, when an OpenAI agent accessed a database in Australia’s national health care system, Albanese said. The government said no personal information was accessed.
OpenAI spokesperson Drew Pusateri said the company learned of the incident in August and notified the Australian government Sept. 10 after completing an extensive review of its models’ activity.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation,” Pusateri said. “In the course of that, our models took actions we did not intend.”
Albanese publicly disclosed the issue after speaking with OpenAI CEO Sam Altman, who is also attending the UNGA. Altman told world leaders Wednesday that governments must find a way to regulate rapidly advancing AI technology.
“We could lose control of the future to AI,” Altman said.
Albanese said an inquiry into the breach would examine whether OpenAI could face criminal charges and why Australian security agencies did not detect the activity before the company disclosed it.
He said he assumed the AI’s interest in the health database was commercially motivated, including to examine spending on specific medicines and changes in those expenditures.
OpenAI revealed last week that it was introducing a new framework to track, investigate and disclose instances of what it calls “misalignment,” including cases in which AI models act without authorization, coordinate with other models or evade oversight.


