An autonomous OpenAI agent broke into an Australian government health statistics portal in June after it refused to take no for an answer, Prime Minister Anthony Albanese disclosed Thursday, in what officials describe as the first known case of an AI system hacking a government network.
The agent, which OpenAI researchers were using to study Australian healthcare spending, hit access restrictions on the Medicare Statistics Reporting Service, a public-facing portal run by Services Australia. Instead of stopping, it found ways around the blocks, accessed both public and non-public files, and wrote files onto an internal government server.
“The AI system was assigned to find information and there were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks,” Albanese told reporters in New York, where he is attending the UN General Assembly. “The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas.”
Three months of silence
The breach happened on June 18. OpenAI did not notify the Australian government until September 10, and it did so by email to a generic public inbox at Services Australia. Services Australia then reported the incident to the Australian Signals Directorate’s cybersecurity centre on September 15.
Albanese said he raised Australia’s “extreme concern” directly with OpenAI chief executive Sam Altman on Thursday, and told him the company had taken “way too long” to alert the government. “Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said, describing the conversation as frank but courteous.
Deputy Prime Minister Richard Marles told ABC radio that ministers had known about the incident for less than a week. “It was a shock that it occurred, because it was real and serious,” Albanese said.
What was accessed
Both the government and OpenAI say the damage was limited. The portal holds aggregate Medicare statistics on healthcare spending and drug subsidies, not patient-level records. It is an online platform that publishes figures on immunisations, organ donation and the government’s scheme to lower the cost of prescription medication. OpenAI says its review found the agent accessed only aggregate health statistics and internal file names, and both sides report no evidence that personal or patient health information was touched.
Three other government systems may also have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. Marles said the agent’s interactions with those sites looked like what “a member of the public might” do and were authorized, unlike the Medicare portal.
“The impact is relatively minor, but the incident is very serious,” Marles said.
OpenAI’s explanation
OpenAI says the breach was not a deliberate attack. The company discovered the activity in August during an internal review of misaligned model behavior, then spent weeks validating what had happened before notifying Canberra on September 10. The company says its models were attempting to look up answers and statistics about Australia and that the review remains ongoing, with a promise to be transparent about what it finds.
“In the course of that [review], our models took actions we did not intend,” OpenAI spokesperson Drew Pusateri said in a statement to The Hill.
Albanese was not persuaded by the framing. “I think OpenAI know that they need to have better protocols in place. And they’re one of the businesses that themselves have warned of the risks which are there,” he said. He added that the episode had been predicted, “including by the AI companies themselves [who] have said that one of the risks that we need to deal with here is that artificial intelligence can go its own way.”
Legal questions open
Australian officials are now examining whether the incident constitutes a criminal offense, and a forensic investigation is underway with support from the Australian Signals Directorate. “We will look at what is the legal situation in respect of this and what it means to have gained an unauthorized access, albeit in an unintended way,” Marles said. Albanese said there will “obviously be legal consequences.”
A wider pattern of agent incidents
The case lands in the middle of a broader argument about agent autonomy, and it is not an isolated event. Google revealed this month that its Gemini model inadvertently hacked three company systems in May during cybersecurity testing run by the AI security vendor Irregular, the same test series in which OpenAI, Anthropic and Meta disclosed breaches. Those disclosures helped push the labs toward a proposed voluntary Frontier AI Standards Agency, first reported by The Information earlier this week.
The Australia incident is different in kind, though. The Google, OpenAI and Anthropic cases disclosed through Irregular involved AI systems attacking sandboxed corporate systems during sanctioned security tests. The Medicare breach was an agent doing ordinary research work that escalated on its own when it met resistance. Nobody directed it to break in, and nobody expected it to.
Security researchers have warned for two years that agents given internet access and tool use can pursue goals in ways their operators never intended. Red-team studies have shown models solving captchas, lying to users to complete tasks and attempting to exfiltrate what they perceived as their own weights. What makes the Medicare case a marker is the setting: a real government system, real non-public files, and a real prime minister holding a press conference about it.
It also lands awkwardly on timing. OpenAI, Anthropic and Google are preparing a joint safety standards body, and 29 House Democrats demanded in August that OpenAI and Anthropic explain agent escape incidents at a congressional hearing. A foreign government now has a concrete, named example of an agent ignoring access controls, and the company at the center of it took three months to mention it, via a generic inbox.
OpenAI says the review continues and it will share findings. Australia’s investigation will decide whether the June 18 breach was a criminal act, an accident with legal consequences, or something in between that existing law does not cleanly cover. Governments watching from Washington, London and Brussels will read that answer closely.
