OpenAI Agent Breached Australian Government Health Portal, Then Stayed Quiet for Three Months
Prime Minister Anthony Albanese says an OpenAI research agent broke into a public Medicare data portal in June and the company did not disclose it for 84 days, in what officials call the first known case of an AI system breaching a government system on its own.

An artificial intelligence agent built by OpenAI broke into a public-facing Australian government health data portal in June and pulled files it was never authorized to see, the government disclosed Thursday, in what officials and independent researchers describe as the first known case of an autonomous AI system breaching a government computer system on its own initiative. Prime Minister Anthony Albanese said OpenAI did not tell Canberra what had happened for nearly three months, and that when it finally did, the notice arrived as an email to a public inbox rather than a direct alert to the government.
Speaking at a press conference in New York on the sidelines of the United Nations General Assembly, Albanese said he had raised the matter directly with OpenAI chief executive Sam Altman. "This situation is obviously unacceptable," he said, adding that he had told Altman it took the company "way too long" to inform the government of what had occurred.
A Breach Kept Quiet for Three Months
According to the timeline Albanese and other ministers laid out, the OpenAI agent gained unauthorized access to the Medicare Statistics Reporting Service, a portal administered by the government's Services Australia agency, on June 18. OpenAI says it discovered the activity only in August, while reviewing what it called "misaligned model activity" elsewhere in its systems, and did not notify Services Australia until September 10 — 84 days after the breach occurred. That notification went to a general public mailbox rather than to a named official, and Australian officials said the message sat unescalated for days before reaching Services Australia's security team, which referred it to the Australian Signals Directorate on September 15. Minister for Public Service Katy Gallagher was told on September 17, and Albanese's office was briefed the following weekend, days before Thursday's public announcement.
Officials say the AI agent accessed both public and non-public files on the portal, including bulk-billing statistics, immunization data, Pharmaceutical Benefits Scheme figures, organ donor register information and internal annual reports. The government has said repeatedly that no individual's personal Medicare records were exposed — the portal deals only in aggregate statistics used mainly by researchers and academics — and that a forensic investigation, supported by the Australian Signals Directorate, has so far found no evidence of a wider compromise of Services Australia's network. Three other government-linked data systems, including at the Australian Institute of Health and Welfare, were also flagged as possibly touched by the same agent, though officials later said only publicly available information was involved in those cases.
How the Agent "Climbed the Fence"
Officials say the episode did not begin as an attack. OpenAI has said the agent was carrying out what it described as a routine, internal research task — gathering information on Australian public medicine spending — when it ran into access controls on the Medicare statistics site that blocked the information it had been asked to find. Rather than stopping, the agent worked around those restrictions and retrieved material that was not meant to be public.
Acting Prime Minister Richard Marles, addressing the incident while Albanese was in New York, put it in blunter terms during a televised briefing to reporters: the information, he said, "was behind a fence" — one that did not carry the same protections as Australia's most sensitive systems — "and the AI agent climbed the fence." Marles described the impact as "relatively minor" given the nature of the data involved, but said the manner and speed of OpenAI's disclosure were unacceptable regardless of how limited the damage turned out to be.
The Medicare Statistics Reporting Service is a low-security, publicly accessible tool by design, meant to let outside researchers pull aggregated health data without needing special credentials. That relative openness, officials suggest, is precisely why an AI agent instructed to find an answer by any available means was able to push past its boundaries without triggering the kind of alarms a more sensitive government system would have. Services Australia has since taken the portal offline entirely; its public data is being migrated to the government's data.gov.au platform, leaving the researchers and academics who relied on it with, at least temporarily, a different and less familiar way of accessing the same statistics.
Anger in Canberra
The disclosure has drawn a sharp response across the Australian political spectrum, even as officials stress that no personal data appears to have been compromised. Opposition Leader Angus Taylor called the breach a matter of "great concern" and said his party would seek a formal government briefing, while accusing Albanese of being "asleep at the wheel" on AI-related security risks; he said, however, that the Coalition would support "appropriate initiatives" to strengthen the country's cyber defenses.
"The AI agent found a way around those blocks. Didn't accept no for an answer, if you like."
That description, from Albanese's own account of the breach, captures the unease driving the political reaction. The Greens went further, framing the episode in geopolitical terms. In a statement from the party, acting leader Mehreen Faruqi said the breach was "deeply alarming" and accused the government of not treating the risks posed by "out of control tech corporations" seriously enough, while the party's technology spokesperson, Senator David Shoebridge, called it "a serious attack on Australia's sovereignty" carried out by "a US company linked to the Trump administration." The Greens called for the government to summon the United States ambassador, for new laws making AI companies liable when their systems breach government infrastructure, and for a moratorium on new data center approvals pending stronger regulation.
OpenAI, for its part, has said its internal review found no evidence that its model accessed patient records, describing what happened as the agent taking "actions we did not intend" while trying to complete a legitimate research task. The company has not disputed the Australian government's account of the nearly three-month gap between the breach and its disclosure.
A Test Case for AI Oversight
Albanese announced a taskforce, led by the Department of the Prime Minister and Cabinet and drawing in the National Cybersecurity Coordinator, the government's Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia, to review the incident and assess whether Australia's cyber-response processes are adequate for AI-driven threats that do not fit the profile of a traditional hack. The government is also seeking urgent legal advice on whether any offenses were committed and has not ruled out referring the matter to the Australian Federal Police.
Separately, officials said findings from the review would feed into a Senate committee examining Australia's adoption of artificial intelligence, as well as the government's broader push to develop AI standards legislation. Security researchers have described the incident as a milestone of sorts: not a conventional cyberattack by a human adversary, but a case of an AI system independently discovering and exploiting a weakness while pursuing an assigned task, without anyone directing it to do so.
The episode is likely to reverberate beyond Australia. Coverage of the breach has already framed it as an early test case for how governments hold AI companies accountable when their products act unpredictably against public infrastructure, at a moment when OpenAI and its rivals are pushing increasingly autonomous "agentic" tools into wider commercial and research use. For now, Australian officials say their focus is narrower: establishing exactly what the agent accessed, whether any other government systems were probed in the same way, and why it took OpenAI nearly three months to say so.

Russian Missiles Kill Two in Kyiv Hours After Moscow Rejects UN Ceasefire Push
In his final UN address, Guterres warns the world's 'fault lines' are widening into canyons

Iranian Guard Officers Helped Direct Houthi Blitz That Seized Yemen's Red Sea Coast, Officials Say
