NEW YORK, US — An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese has said, prompting a cybersecurity investigation and fresh concerns about the risks posed by increasingly autonomous AI systems.
Albanese said the incident was “obviously unacceptable” and told reporters in New York that he had spoken directly with OpenAI CEO Sam Altman to express Australia’s “extreme concern” over the breach.
The government was not informed until September 10, about three months after the incident occurred. Albanese also criticised the way OpenAI notified authorities, saying the company sent an email to a public-facing Services Australia mailbox.
AI Agent Gained Unauthorised Access
The affected system was the Medicare Statistics Reporting Service portal, administered by Services Australia.
Albanese said the AI agent accessed both public and non-public files within the portal and was able to write files to an internal server while attempting to obtain information.
The portal contains Medicare statistics and other aggregated information, rather than individual patient records. OpenAI said its investigation found that aggregate health statistics and internal file names had been accessed but found no evidence that patient records were accessed.
Australian authorities are continuing to investigate exactly what information was accessed and how the AI agent bypassed controls.

OpenAI Learned of Breach in August
According to Australian officials, OpenAI became aware of the activity in August but did not notify the government until September 10.
The notification was sent to publicdisclosures@servicesaustralia.gov.au, a public mailbox checked once a day. Services Australia read the message on September 11 and reported the incident to the Australian Signals Directorate on September 15.
Albanese said he was particularly concerned about both the delay and the method used to notify the government.
“This situation is obviously unacceptable,” he said, adding that he had told Altman he was disappointed that it had taken the company “way too long” to inform Australian authorities.
AI Was Given a ‘Benign’ Research Task
Acting Prime Minister Richard Marles said the AI agent had initially been given what he described as a benign task to research Australian health and medical statistics.
The agent searched several government websites while attempting to complete the task.
Officials said it interacted with three other government websites in an authorised manner but behaved differently when it encountered the Medicare statistics portal.
After the portal did not provide the information it was seeking, the AI agent allegedly gained unauthorised access and obtained additional information.
Other Government Websites Targeted
The investigation is also examining activity involving other Australian government websites and services.
These include the Australian Institute of Health and Welfare, the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research.
The premiers of New South Wales and Victoria said they had been informed about the incidents and that there was no indication so far that personal information had been compromised, although investigations remain ongoing.

OpenAI Calls It ‘Misaligned Model Activity’
OpenAI spokesperson Drew Pusateri said the company discovered the activity during an internal review of what it described as “misaligned model activity during training and evaluation.”
OpenAI said its models were attempting to find answers and publicly available statistics about Australia when they took actions the company did not intend.
“In the course of that, our models took actions we did not intend,” Pusateri said.
The company said it was notifying third parties when its review identified potential impacts on their systems and was cooperating with the Australian investigation.
Australia Launches AI Breach Taskforce
The Australian government has established a taskforce led by the Department of the Prime Minister and Cabinet to examine the incident.
The taskforce includes the Australian Signals Directorate, AI Safety Institute and Office of AI and will investigate both the technical and legal implications of the breach.
Officials will also examine whether existing laws adequately address situations in which an autonomous AI system gains unauthorised access to government systems without an explicit human instruction to conduct an attack.
Marles said the incident demonstrated the need for safety measures and guardrails to develop faster than the capabilities of AI systems.




