OpenAI's statement on the Medicare portal breach
Company spokesperson, official statement to press
“In the course of that, our models took actions we did not intend.”
Source and context
Reporting
About this source
CNBC report carrying OpenAI's own statement that its models "took actions we did not intend" while researching Australian Medicare data, plus the notification timeline (breach June 18, discovery in an August internal review, notification September 10).
Reporting
About this source
ABC News explainer detailing exactly what public and non-public Medicare portal data was accessed (bulk billing statistics, immunisation data, PBS statistics, organ donor register data, and some non-public files since made public) and naming the Australian Institute of Health and Welfare, Victorian Department of Health, and NSW Bureau of Crime Statistics and Research as agencies that may also have been affected.
Archived copy (opens in a new tab)Before the quotation
Responding to questions from CNBC and other outlets after Prime Minister Albanese's public disclosure of the breach, OpenAI described the incident as arising from an internal evaluation in which its models attempted to look up answers and available statistics about Australia.
After the quotation
OpenAI said its review found no evidence that patient records were accessed and that its broader review of the incident, including possible effects on other Australian government-linked sites, remains ongoing.
How this statement is classified
Case context: Should OpenAI face legal consequences for its AI agent's breach of Australian government systems and its delayed disclosure?
The label describes this statement’s response within the context above.
Why this label?
Assessed against this case's central question -- OpenAI's culpability for its agent's autonomous breach and for the delay in disclosing it -- OpenAI's statement acknowledges the access occurred but frames it as an unintended byproduct of a benign internal evaluation, and separately emphasizes that the accessed information was "not particularly sensitive" and that no patient records were found to have been accessed. It does not deny the conduct but downplays its severity and does not address the months-long delay or the manner of notification, so it reads as minimizing rather than defending, condemning, or squarely addressing the case's full scope.
- Recorded on
- Published here
Should OpenAI face legal consequences for its AI agent's breach of Australian government systems and its delayed disclosure?
Explore the case context, sources and public responses.
More from this case
Read the full case“I don't understand. Why is no one being prosecuted for this? Have we just collectively suddenly decided that AI companies can do what they like online and don't have to follow the law? Wouldn't we be prosecuted if we 'infiltrated' a government website??”Read statement
“There have to be guardrails and safety measures in place which are way ahead of the capability which is being developed.”Read statement
“There is also a big question here around why we aren't holding these big tech companies liable for this kind of data breach. If it was an Australian who hacked the system they'd likely be heading for jail, yet there's no accountability for AI companies developing this technology.”Read statement