Australia vows AI guardrails after unprecedented OpenAI breach - ABC News & Headlines – Australian Broadcasting Corporation

Direct Source Verification: This story is aggregated from ABC News Australia (abc.net.au). Full reporting rights and copyright belong to the primary publisher.
Australia vows AI guardrails after unprecedented OpenAI breach  ABC News & Headlines – Australian Broadcasting Corporation

Anthony Albanese spoke to OpenAI chief Sam Altman (pictured) to express his "disappointment" before revealing the breach. (Reuters: Kim Kyung-Hoon)

OpenAI's handling of a rogue agent that accessed government data has strengthened Australia's push for strict rules around AI transparency and incident reporting.

The federal government will pursue strong safeguards despite US resistance to ensure the country is not at the "mercy" of foreign artificial intelligence companies.

A task force is undertaking a rapid review of the OpenAI incident to examine legal gaps and inform new AI national standards.

An unprecedented breach of a government website by a rogue OpenAI agent will sharpen Australia's push to impose stricter safety, transparency and reporting requirements on artificial intelligence companies.

Findings from a "rapid" forensic investigation into the incident will fold into the federal government's existing work to develop national AI standards that govern how the technology operates in Australia.

Despite resistance from the Trump administration, Australia will impose "guardrails" on AI, with Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton declaring tech companies should not be unleashing unsafe models.

"I think what we're observing at the moment is that a number of the AI models … that they have inside their companies are not safe and they have a lot more work to do to make them safe before they release them to the public," he told the ABC.

OpenAI has been criticised for failures around when and how it notified the government that an autonomous agent had gained unauthorised access to Medicare statistics hosted on an old Services Australia online portal.

The breach, which researchers have called the "first" autonomous hack of a government website, occurred in mid-June but went undetected by OpenAI for two months, with the company taking another four weeks to alert Australia.

Andrew Charlton says tech companies have work to do before they release AI models to the public. (ABC News: Matt Roberts)

The tech company has yet to explain the communication breakdown or why it only informed Australia via a generic email to a low-level government inbox.

While the government believes no personal information was accessed, the OpenAI breach has exposed Australia's current reliance on voluntary disclosure of incidents and laid bare gaps in existing laws.

Mr Charlton said the OpenAI incident was a "very stark" demonstration of the risks the government was seeking to manage with new AI standards due to be unveiled by the end of this year.

"Incident reporting needs to be timely, and the nature of the reporting needs to be fulsome and directed in the appropriate place," he said.

"The report that was made by OpenAI fell short of those requirements."

He said the breach "makes the case" for the government's safety priorities.

"It also provides the justification … for our determination to make sure that we have Australian AI, that we shape technology, we have sovereign capability in Australia, and we aren't entirely at the mercy of foreign AI companies," he said.

He said Australia wanted the US and China, which are the source of the largest and most capable AI models, to be "actively engaged" in the discussion about guardrails.

But confirmed the government would work with other like-minded countries to tackle the issue regardless.

Anthony Albanese says an OpenAI agent breached the Services Australia website. (ABC News: Adam Kennedy)

"The government will do what we need to do to make sure that we keep Australians safe," he said.

Mr Charlton said Australians were looking carefully at the risks posed by AI and "yet to be convinced" that companies had those risks under control.

"I think for that reason there's a lot of work to do [for AI companies] to rebuild social license," he said.

Mr Charlton said AI companies had been receptive to the "high bar" Australia intended to impose on them.

Sam Altman at a session about artificial intelligence during the 81st United Nations General Assembly. (Reuters: Brendan McDermid)

Prime Minister Anthony Albanese confirmed the breach on the sidelines of the United Nations General Assembly in New York shortly after a "frank" discussion with OpenAI's chief executive Sam Altman.

He said OpenAI had taken "way too long" to inform the government and was scathing of the "unacceptable" form of the alert.

In a statement, an OpenAI spokesperson said the company was "conducting an extensive review of misaligned model activity" during training.

Shadow Defence Minister James Paterson told 7.30 that Australians were entitled to demand an explanation, but ultimately the issue before the government was how to have a degree of influence and "sovereign control" over the technology.

He said if frontier AI companies chose Australia as their second home for training models outside the US, that would put the country in a position to "demand access".

"We would have an opportunity to have a say in global AI regulation," he said.

The government on Thursday launched a task force to investigate and assess gaps in Australia's existing laws around reporting requirements and enforcement and cyber protections.

It is also investigating if the OpenAI incident broke any Australian laws, though government sources said the initial view was that this was unlikely.

Ensuring AI companies are held liable for the actions of their autonomous agents and stronger penalties to encourage the use of safeguards has emerged as a key priority in the wake of the breach.

Ensuring AI companies are held liable for the actions of their autonomous agents has emerged as a key priority in the wake of the breach. (Reuters: Dado Ruvic)

The OpenAI incident began on June 18 when an AI agent tasked with researching public medicine spending autonomously gained unauthorised access to a Services Australia portal after initially being denied the information it sought.

It collected non-public aggregate health statistics and internal files from what was effectively an old Australian government website that carried non-personal Medicare data.

The breach went undetected until OpenAI identified it on August 11 during a review of its models' activity.

June 18: A Medicare statistics reporting service portal, administered by Services Australia, is breached by an OpenAI agent.

August 11: OpenAI becomes aware of the breach during a review of OpenAI misaligned model activity during training.

September 1: OpenAI chief executive officer Sam Altman meets Defence Minister Richard Marles in San Francisco, but Mr Marles says the breach was not disclosed.

September 10: OpenAI sends an email to publicdisclosures@ servicesaustralia.gov.au — an address used by academics and researchers to notify weaknesses in Services Australia's systems.

September 11: Services Australia sees the email.

September 15: Services Australia notifies the Australian Signals Directorate (ASD).

September 17: Government Services Minister Katy Gallagher is told and seeks further information.

September 19-20: Prime Minister Anthony Albanese and his office are informed of the incident, while Senator Gallagher holds several discussions with Mr Marles, Home Affairs Minister Tony Burke, Services Australia and the ASD.

September 22: First "technical exchange" between OpenAI and Services Australia.

September 24: Mr Albanese calls Mr Altman and informs the public of the breach.

It would take another month before the company informed Australia of the incident, during which time Deputy Prime Minister Richard Marles met with Mr Altman, though the incident was not raised.

When OpenAI did eventually alert the government on September 11, it was via a generic email sent to a Services Australia inbox that was only checked once a day.

Staff discovered the email the next day and, after verifying the report, alerted the Australian Signals Directorate on September 15.

Government Services Minister Katy Gallagher was briefed two days later, and she then held a series of discussions with senior ministers and Mr Albanese.

It took until Tuesday this week before the Australian government was able to get a technical briefing from OpenAI about the incident.

That same day, US President Donald Trump used an address to the UN General Assembly to dismiss international calls for guardrails on AI.

Donald Trump addressed the 81st United Nations General Assembly, pushing back against AI regulation. (Reuters: Mike Segar)

He said the United States "rejects any attempt to construct a globalist scheme to control" AI.

Australia had been among 22 signatories to an urgent statement issued on the eve of the summit warning the pace of AI development could "outpace" the world's ability to "manage emerging risks".

Despite the Trump administration's resistance to global AI rules, frontier companies like OpenAI and Anthropic have publicly acknowledged the need for safeguards.

Speaking at the UN Security Council on Thursday shortly before Australia went public with the OpenAI incident, Mr Altman acknowledged the need for "speedy and accurate" reporting of incidents involving AI.

Original Source
https://www.abc.net.au/news/2026-09-25/openai-breach-builds-case-for-tough-ai-rules/107192992
Visit ABC News Australia ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business