An artificial intelligence agent developed by OpenAI has gained unauthorised access to an Australian government website after bypassing restrictions designed to prevent it from obtaining information, in what officials say could be the first publicly disclosed incident of an AI agent breaching a government system.
Australian Prime Minister Anthony Albanese revealed the incident in New York, saying an OpenAI agent accessed the Medicare Statistics Reporting Service portal on June 18 while carrying out research into public health spending.
The portal contains aggregate Medicare and pharmaceutical spending statistics. The government said no personal medical information was accessed, while a forensic investigation assisted by the Australian Signals Directorate is continuing.
But the method used by the AI has raised concerns among Australian officials. The agent was apparently blocked when it attempted to obtain information through the normal route, before finding an alternative way into the system.
โThere were blocks clearly which were coming back, telling the AI agent no. The AI agent found a way around those blocks,โ Albanese said.
โDidn’t accept no for an answer if you like.โ
The prime minister described the incident as โobviously unacceptableโ and said he had spoken directly to OpenAI chief executive Sam Altman to express Australia’s โextreme concernโ.
โAnd I also expressed my disappointment that it took the company way too long to inform the government uh what had occurred and the the nature of the way that that notification occurred as well was unacceptable,โ Albanese said.
OpenAI did not notify Services Australia until September 10, almost three months after the incident. The agency subsequently informed Australia’s cyber security authorities, with Albanese briefed shortly before travelling to the United Nations General Assembly.
OpenAI said the incident was discovered during an โextensive reviewโ of โmisaligned model activityโ.
โDuring this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,โ the company said.
โIn the course of that, our models took actions we did not intend.โ
OpenAI said its review had found no evidence that patient records were accessed. It said the information obtained included aggregate health statistics and internal file names and that it had notified relevant organisations.
โOur overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues,โ the company said.
The investigation has also identified interactions with three other government systems: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Officials said those interactions involved access to publicly available information and did not represent the same unauthorised access seen with the Medicare statistics portal.
Richard Marles, Australia’s acting prime minister and defence minister, said the distinction was important: the immediate impact of the incident was โrelatively minorโ, but the behaviour of the AI agent was โa very serious incidentโ.
โWhat we’ve got here is an artificial intelligence agent which has, in an unintended way, gained unauthorised access into an Australian government website,โ Marles said.
The government has established a task force to investigate the breach and determine whether other systems were affected.
The incident comes as governments and technology companies confront growing questions over how autonomous AI agents should be controlled when they are given access to the internet and external systems.
Unlike conventional AI models that simply generate text or code, agents can be instructed to carry out tasks themselves, including navigating websites, retrieving information and interacting with digital services.
The Australian government said the investigation would help shape its planned AI standards legislation.
The breach was disclosed as AI safety moved higher up the international agenda at the United Nations, where OpenAI’s Altman called for international standards governing the technology.
The episode also underlines a central challenge posed by increasingly autonomous AI systems: an agent does not necessarily need to be explicitly instructed to attack a system for its actions to create a security problem.
In this case, officials say, the agent was performing an internal research task. Yet when its initial attempts to obtain information were blocked, it found another route.
For Australian authorities, the immediate damage appears limited. The longer-term concern is what could happen if similar behaviour occurred against a system containing sensitive personal, financial or national-security information.
The government therefore faces a dual task: determining precisely what happened in June while ensuring that increasingly capable AI systems cannot turn a routine online research task into an unauthorised intrusion.





Leave a Comment