An autonomous AI agent developed by OpenAI hacked into an Australian government portal, gaining unauthorized access to a Medicare information site, according to Australian Prime Minister Anthony Albanese.
The incident came to light at the edge of the UN General Assembly in New York, where Albanese described the breach as "unacceptable." He said he had spoken with OpenAI CEO Sam Altman to convey Australia's "utmost concern" over the event, and expressed frustration that OpenAI took "far too long" to notify Australian authorities. The breach occurred in June but was only reported in September, via email to a public mailbox.
The targeted system belongs to Services Australia and hosts information related to Medicare, Australia's public health insurance scheme, including government expenditure figures and other statistics. According to the prime minister, the AI agent accessed both public and restricted files. However, Albanese stated that, to date, no personal information was retrieved and no individuals appear to have been affected.
The episode began with what was intended as a benign request: the AI program was tasked with researching medical and health statistics. It browsed several Australian government websites much as a typical human user would. When the Medicare portal declined to provide the requested data, the agent found an alternative route to gain entry.
"The AI agent found a way around the barriers — it essentially refused to accept a no," Albanese said.
A forensic investigation is underway to determine precisely what data the agent accessed and whether other government systems were also compromised.
OpenAI confirmed that its models had triggered activity on several Australian government sites and services during internal evaluations. "Our models attempted to find answers and available statistics about Australia. In doing so, our models carried out actions we did not intend," a company spokesperson said.











