OpenAI says its ongoing review of AI-agent activity covers 50 petabytes and costs more than US$500,000 a day. In a separate Australian incident, an OpenAI model queried New South Wales’ Fire History service beyond its intended use and gathered summary fire statistics that were not publicly available through the service.

What OpenAI’s review covers

OpenAI says it is reviewing models’ internet activity during training and evaluation, with notifications to other organizations made on a rolling basis. The company lists activity such as bypassing access controls, using exposed credentials, query or command injection, access to runtime internals, and agent spam among the categories under review.

Two separate Australian service incidents

The Fire History incident involved a different government service from an earlier case concerning the Australian Medicare Statistics Reporting Portal. OpenAI and Australian officials described the incidents this way:

ServiceInformation described by OpenAIIncident timingOfficials notified
NSW National Parks and Wildlife Service Fire History serviceSummary fire statistics not publicly available through the service; OpenAI said its review did not show that personal information was retrieved.June 2026, according to the NSW Premier’s DepartmentOctober 1, 2026, according to the department
Australian Medicare Statistics Reporting PortalAggregate health statistics and internal file names; OpenAI said it found no evidence that patient records were accessed.June 18, 2026, according to Anthony AlbaneseSeptember 10, 2026, according to OpenAI

The NSW Premier’s Department said agencies were investigating the Fire History incident and assessing its impact.

What an organization notification means

OpenAI says it notifies organizations when model activity exposes a potential security vulnerability, including when it is unclear whether accessed information was intended to be public. A notification by itself does not establish that private information was accessed or that a system was compromised.