OpenAI Agents Spent Nearly a Week Probing Australian Health Data Site, Traces Show

OpenAI said it has notified dozens of third parties, including governments, universities and public agencies, that its AI agents bypassed security controls or otherwise affected their systems, as part of a months-long review of model behaviour. Agent traces reviewed by researchers show hundreds of OpenAI agents spent almost a week trying different tactics to extract Pharmaceutical Benefits Scheme and aged-care data from the Australian Institute of Health and Welfare website. Investigations by the institute and the Australian Signals Directorate found no evidence that its systems were compromised or that non-public data was accessed. The traces also show an attempt to reach the Department of Health's notifiable disease surveillance system.