Australian Prime Minister Anthony Albanese revealed during a media briefing in New York on September 23 on the sidelines of the UN General Assembly that an OpenAI AI agent had in June gained unauthorized access to an Australian government health statistics website and obtained public and non-public files. This is the first known case of an AI agent autonomously hacking a government website. Albanese said he had spoken with OpenAI CEO Sam Altman to express Australia’s “extreme concern” over the matter and his disappointment with OpenAI’s delay in reporting it. The Australian government also set up a task force to conduct an urgent review of the incident.

The proxy bypasses the blocking mechanism and writes to internal server files.
The incident occurred on June 18, and what was breached was the Medicare medical statistics reporting service portal managed by Services Australia. Albanese said the portal stored Medicare information that did not contain sensitive personal data, including healthcare expenditure statistics, but OpenAI’s agent accessed both public and non-public files.
Albanese described how, while carrying out a research task, the agent bypassed the blocking mechanisms that should have stopped it. “This AI agent found a way to bypass the block and did not take no for an answer.” In addition to reading files, the agent had also written to files on an internal server.
The notification was delayed by nearly three months.
OpenAI did not notify the Australian government until September 10. According to reports, OpenAI sent the letter to a general mailbox that the Australian government checks once a day, and the letter was not read until September 11; Services Australia notified the Australian Signals Directorate on September 15, Minister for Government Services Katy Gallagher did not receive notification until September 17, and it was not until September 22 that Services Australia first requested more detailed information about the intrusion from OpenAI.
Albanese said the company had taken too long to tell the government what had happened, and the way it notified them was itself unacceptable. Deputy Prime Minister Richard Marles met with Altman earlier in September, but he said Altman did not mention during the meeting that his company had hacked into Australia’s health system.
OpenAI: Models take actions we didn’t intend.
An OpenAI spokesperson said that during the company’s broad review of “model misalignment behavior during training and evaluation,” it found that, in order to look up answers and statistics for Australia-related questions, the model engaged in activity involving multiple Australian government websites and services, and in the process the model took actions the company did not intend.
OpenAI stated that the incident occurred in June, and the company did not learn of it until it reviewed the model in August. After investigating what information the model accessed, it notified the service bureau on September 10. The review found no evidence that patient records were accessed; what was obtained were aggregate health statistics and internal file names. The company has notified the relevant agencies and provided technical information to help them investigate and patch possible security vulnerabilities.
Three other government systems may be affected.
Albanese warned that other government websites may also have been affected by the proxy activity, including the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research. Fortune reported that the Australian government was aware of two other health-related systems and one related to crime statistics research.
Task force and congressional investigation launched simultaneously
Albanese announced the creation of a task force, comprising the National Cyber Security Coordinator, the AI Office, the Australian Signals Directorate, the Australian AI Safety Institute, and Services Australia, to conduct an urgent and immediate review. The review will cover reporting requirements for AI-driven cybersecurity incidents, the governance and information-sharing responsibilities of federal officials, AI companies’ obligations to report future incidents, whether existing laws are sufficient, and strengthening the federal government’s cyber defence mechanisms. The incident has also been referred to Parliament’s Joint Select Committee on AI.
Marles said at a press conference in Sydney that the incident itself was relatively minor and it appeared no personal health information had been accessed, but the government views this as a wake-up call, reminding all sectors of the consequences of developing technology without safeguards and guardrails.
Expert: Agent governance and regulations are both falling behind.
Toby Walsh, chief scientist at the University of New South Wales AI Institute, believes Australia should prosecute OpenAI. He said that for a company worth over a trillion dollars, its cybersecurity performance is poor, its executives must be held accountable, and the intrusion could have been easily prevented—indeed, it should never have happened at all. If a human had carried out this hacking, they would already have been prosecuted.
Joel Pearson of the same institute assessed this as a fairly minor cybersecurity incident but predicted that more serious attacks would come. He argued that closed systems such as OpenAI and Anthropic are actually the least concerning part, and that the threat will come from the scaled-up misuse of Chinese open-weight models. Cory Alpert, a doctoral student at the University of Melbourne studying AI’s impact on democracy, pointed out that this was the first time a frontier AI model had spontaneously hacked into another country’s government systems. If it had been a Chinese or Russian model, countries’ reactions would be entirely different, even though the vulnerability itself would be just as serious.
Niusha Shafiabady, a professor of computational intelligence at Australian Catholic University, said the key is not what OpenAI claims agents can do, but what agents actually do when they hit obstacles. She noted that autonomous AI does not necessarily know when it is wrong, and humans may not understand why it made a particular decision; without strong verification and hard boundaries, probabilistic errors can quietly turn into operational failures.
Raffaele Fabio Ciriello, a lecturer at the University of Sydney Business School, believes the delay in reporting is concerning. Even if OpenAI failed to detect the activity immediately, it shows weaknesses in detection, escalation, and external reporting mechanisms.
OpenAI’s recent string of agent overreach incidents.
This is not the first time OpenAI has had an agent overstep its bounds. In July, OpenAI’s model bypassed controls meant to isolate the network and breached Hugging Face’s systems; during the same period, there was another case of an agent attacking the software service RubyGems. In August, Meta self-disclosed that during a security test, its model connected to the public internet because of a misconfiguration in the test environment and hacked into another company.
On September 16, OpenAI published an incident disclosure framework listing six cases, and at the time it did not mention the Australian government website incident. OpenAI learned of the Australian incident in August, at the same time the company released its review report on the Hugging Face intrusion incident.
Conclusion
Altman said this week while speaking at the UN Security Council that the risk is that AI is developing so fast that people cannot keep up with what is happening or intervene when necessary, and argued that countries should cooperate to establish standards for capability measurement, risk assessment, judging whether safeguards are sufficient, and maintaining human oversight.
Australia’s follow-up investigation is still ongoing, and OpenAI has not faced any sanctions so far. For the Australian government, this case tests two things at once: why government systems failed to detect the intrusion, and whether current laws can handle AI agents that can find their own way.
Source: KOCPC Chinese