Executives from OpenAI, Anthropic, Microsoft, and Google to front joint Australian AI committee

OpenAI says its review in response to the Medicare and Hugging Face agent attacks is costing the company more than US$500,000 per day as it works through 50 petabytes of data — roughly 50 million gigabytes.

The company disclosed Friday that its agents hacked into a New South Wales government website in June, accessing historical non-public data on bushfires. OpenAI discovered the latest breach Tuesday and informed the state government and the Australian Signals Directorate after a 48-hour review. It is the sixth Australian government website to be notified by the AI company since last month.

“We’re working back through the records month by month, looking for potential unintended activity beyond the cases we’ve already found,” OpenAI said in a blog post this week.

“To put that in perspective, if that were all plain English text, it would take one person about 66 million years to read it at 240 words a minute, reading nonstop without ever sleeping or taking a break,” OpenAI said.

The company said it is using AI to sift through the records and plans to increase its computing power as the process is refined. OpenAI is searching records for where its models accessed and changed websites, or took actions involving passwords, application programming interface (API) access, or other sensitive credentials.

The NSW bushfire disclosure came weeks after Prime Minister Anthony Albanese announced that OpenAI’s agents had hacked into Services Australia’s Medicare statistics portal. The reason for the delay in disclosing the NSW breach compared to the revelation of the Medicare attack is due to the sheer volume of data OpenAI needs to review. The Medicare breach has since prompted the Australian government to require departments and agencies to undertake a stocktake of legacy technology to reduce the number of ageing systems within government and reduce the cybersecurity risk they may present in the event of an AI agent attack.

As of late last month, more than 100 organizations had been notified that they were targeted by OpenAI’s agents, though the company said being notified does not mean private information was accessed or that a system was compromised. OpenAI said it expects to find more cases and notify more organizations about events that may have occurred months ago.

Executives from OpenAI, Anthropic, Microsoft and Google are scheduled to front a joint parliamentary committee on artificial intelligence in Sydney on Tuesday. OpenAI said organizations will be informed privately if they need to investigate and address potential security issues, and that it will publicly report findings about agent behavior and identified weaknesses in safeguards for the broader AI sector.

“We err on the side of notification when our models’ activity exposes a potential security vulnerability, even in cases where it is unclear if the information accessed was intended to be public, so the organization can investigate and take appropriate action,” OpenAI said.