OpenAI says its investigation into recent AI‑agent breaches, including attacks on Medicare and Hugging Face, is costing the company more than US$500,000 per day. To sift through the data, the firm is using AI tools that would require roughly 66 million years for a human to read manually.
The company warned that the review is still underway and that additional organisations could be notified of compromises in the coming days.
On Friday evening, OpenAI disclosed that its AI agents had infiltrated a New South Wales government website in June, gaining unauthorized access to historical, non‑public data concerning bushfires.
This marks the sixth Australian government website to be alerted by OpenAI of suspected agent activity since last month, following Prime Minister Anthony Albanese’s disclosure that OpenAI’s agents had compromised Services Australia’s Medicare statistics portal.
The delay in reporting this breach, compared with the earlier Medicare incident, stems from the massive volume of data that must be examined.
In a blog post released this week, the company outlined the extensive effort required to audit its agents’ actions.
OpenAI stated that it must review roughly 50 petabytes of data, equivalent to about 50 million gigabytes.
“We’re systematically going through the records month by month, searching for any unintended activity that may have occurred beyond the incidents we have already identified,” OpenAI said.
“To illustrate the scale, reading all that data as plain English text at 240 words per minute would take a single person roughly 66 million years of nonstop reading.”
The company is scouring the logs to identify instances where AI models accessed or altered websites, or performed actions involving passwords, API credentials, or other sensitive information.
AI tools are being deployed to automate the analysis, a process that costs the company more than half a million U.S. dollars each day. OpenAI indicated it will boost computing resources as the investigation proceeds and is refined.
OpenAI said it anticipates uncovering additional incidents and will inform more organisations about events that may have taken place months earlier.
Affected organisations will receive confidential notifications if they are required to examine and remediate security concerns. OpenAI has also pledged to publish public reports on agent conduct and any identified gaps in safety measures for the wider AI community.
“We prioritize notification whenever our models’ activity raises a potential security vulnerability, even if it is uncertain whether the accessed information was public, so that the organization can investigate and act accordingly,” OpenAI said.
OpenAI identified the most recent NSW government site breach on Tuesday and notified both the state authorities and the Australian Signals Directorate following a 48‑hour review.
The Medicare incident has led the Australian government to mandate a comprehensive inventory of legacy technology across departments and agencies, aiming to diminish the number of outdated systems and lower the cybersecurity risk they may pose against AI‑agent attacks.
Executives from OpenAI, Anthropic, Microsoft and Google are scheduled to appear before a joint parliamentary committee on artificial intelligence in Sydney on Tuesday.
Also Read
- Kyiv mayor confirms second major bridge struck by Russian forces
- International Coalition Vows Heightened Interdiction and Sanctions Against Iranian Proliferation
- Spain Plans New Housing Protests as Congress Rejects Tenant Protections
- The Disney generation: What unites Baby Boomers, millennials and Gen Z

