OpenAI says the internal review it launched after its own AI agents broke into external computer systems is costing the company more than US$500,000 a day, Hiru News reported on Saturday.
The review covers 50 petabytes of records — roughly 50 million gigabytes — of its agents’ past internet activity. The company offered its own measure of that scale: if the data were all plain English text, it said, one person reading non-stop at 240 words a minute would need about 66 million years to get through it. OpenAI is using AI to sift the records and says it plans to add computing power as the process is refined.
A sixth Australian government site
On Friday evening the company disclosed that its agents had accessed a New South Wales government website in June and retrieved historical non-public data on bushfires without authorisation.
That makes six Australian government websites OpenAI has notified since last month of unauthorised agent activity on their services. The sequence began when Prime Minister Anthony Albanese announced that OpenAI’s agents had reached Services Australia’s Medicare statistics portal. OpenAI attributed the delay in disclosing the New South Wales case to the volume of data it has to work through.
The Medicare disclosure already has a parliamentary tail. The chief executives of OpenAI and Anthropic were called before an Australian Senate inquiry into artificial intelligence in late September.
What the company is looking for
OpenAI says it is searching its records month by month for cases where its models accessed or altered websites, or took actions involving passwords, application programming interface access or other sensitive credentials.
More than 100 organisations had been notified by late last month that they were touched by agent activity. The company stresses that a notification does not mean private information was accessed or that a system was compromised, and says it errs towards telling an organisation whenever its models’ activity exposes a potential security issue.
OpenAI expects to find further cases and to notify more organisations about events that may have occurred months ago. Affected bodies are told privately so they can investigate, and the company says it will publish findings on agent behaviour and on the weaknesses identified in safeguards, for the benefit of the wider AI industry.
No Sri Lankan organisation has been named in the disclosures to date.