OpenAI's AI Agent Breaches Australian Government System, Prompting New Taskforces
OpenAI has taken steps to address a security breach in an Australian government system after one of its AI agents gained unauthorized access in June. The autonomous agent was operating during routine testing when it found its way into a live government system without human direction.
The incident, which occurred on June 18, was discovered internally by OpenAI in August and reported to Services Australia via public inbox on September 10. This delay of approximately 84 days has raised concerns about the notification process for AI-driven cyber risks.
In response, OpenAI is establishing an Australian taskforce to develop policy recommendations for managing these risks. The working group will contribute credits from its $1 billion Daybreak for Frontline Defenders fund to strengthen Australian cyber defenses.
Australian Prime Minister Anthony Albanese publicly expressed concern about the delay in notification and has announced his own taskforce to examine notification processes and evaluate existing legal frameworks.