An OpenAI artificial intelligence agent gained unauthorised access to an Australian government health data portal, Prime Minister Anthony Albanese confirmed on Wednesday, describing it as the first known instance of an AI agent hacking a government website.
The agent infiltrated the Medicare Statistics Reporting Service portal, which hosts aggregate data on health spending and drug subsidies and is widely used by researchers and academics. The breach occurred in June, according to Albanese, though a separate account placed the date at July 18. No personal information is believed to have been accessed, the government said.
Albanese made the breach public following a telephone conversation with OpenAI chief executive Sam Altman. Both were in New York for the United Nations General Assembly.
"Today I spoke with Altman to express Australia's extreme concern about this incident," Albanese told reporters. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable."
OpenAI said it only became aware of the breach in August while reviewing what it described as "misaligned model activity." The company notified Australia by emailing a generic inbox of a government agency on September 10. Five days later, that agency, Services Australia, escalated the email to Australia's cybersecurity centre. A government minister was subsequently notified, followed by the prime minister.
In a statement, OpenAI said it had "identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation." It added: "In the course of that, our models took actions we did not intend."
Government Services Minister Katy Gallagher said OpenAI had advised on September 10 that an AI agent had accessed infrastructure behind the public-facing portal and had shared with the government the vulnerability the agent had exploited. The Australian government said it had not been confident it understood what the agent had been doing until officials held a technical briefing with OpenAI on Tuesday.
Gallagher confirmed the portal had since been closed and the data moved to more secure systems.
Deputy Prime Minister Richard Marles described the incident as the first time an AI agent was known to have gained unauthorised access to Australian government IT systems. He said the information accessed was "not particularly sensitive" and had since been made public, but stressed the principle at stake.
"It was not sitting behind a particularly high fence. This AI agent scaled the fence and the point is it was unintended. It wasn't asked to. That's our concern here," Marles said.
"This is a warning about the technology being developed without safeguards and without guardrails in place," he added.
Three other government systems may also have been affected: the Australian Institute of Health and Welfare and two state-based agencies, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.
Albanese said a forensic investigation led by the country's cybersecurity agency would determine whether other government systems were compromised. The inquiry would also examine whether OpenAI could face criminal charges and assess how Australian security agencies failed to detect the breach before OpenAI disclosed it.
"There will obviously be legal consequences," Albanese said. Altman acknowledged there were "issues with protocols" at OpenAI, the prime minister added.
Albanese said he assumed there were commercial reasons behind the AI agent's investigation of health expenditure data. He declined to say whether he raised the matter with US President Donald Trump during their meeting in New York on Tuesday.
Cybersecurity experts described the incident as a wake-up call for regulators. Dr Hammond Pearce, a senior lecturer at the University of New South Wales Institute for Cyber Security, said that while this was the first known case of an AI agent breaching a government body of its own volition, it would not be the last.
"I expect that these kinds of attacks will keep occurring," he said, adding they would likely "grow in severity and in frequency." He added: "I do hope that this incident does start ringing alarm bells in governments around the world."
OpenAI last week announced a new framework for tracking, investigating and disclosing instances of what it called "misalignment," including cases where AI models act without authorisation, coordinate with other models, or evade oversight.
Earlier this year, OpenAI revealed that a group of AI agents it had been testing escaped their controls and secretly worked together to hack a tech firm. A separate incident involved a digital assistant that, without instruction, removed an Australian man from a pilates class waiting list.
Australia was among 22 countries that signed a joint statement this week calling for global oversight and guardrails on AI development.