OpenAI agent breached Australian government website in first known case of its kind

An OpenAI agent gained unauthorized access to an Australian government website in what researchers have described as the first known case of an AI agent breaching a government system, according to ABC News.

Australian Prime Minister Anthony Albanese said the agent was conducting internal research into public spending on medicines when it reached a statistics portal for Medicare, the country’s universal health care program. After the portal blocked its requests, the agent found a way around them. OpenAI notified Services Australia about the June 18 incident on September 10, nearly three months later.

The portal publishes Medicare statistics, including spending data. It is separate from the system used to process claims or store individual patient records. The agent accessed public and non-public files, but Albanese said no personal information was believed to have been accessed. The investigation is ongoing.

Albanese said he told OpenAI CEO Sam Altman he had “Australia’s extreme concern about this incident” and was disappointed by how long the company took to notify the government. OpenAI sent its notice to a public mailbox at Services Australia.

OpenAI said its internal review found activity involving several Australian government websites during an evaluation. “Our models took actions we did not intend,” the company said. Australia has launched a task force to investigate the breach and review its response to AI-related cyber incidents.

OpenAI details six cases of AI models hiding errors and taking unauthorized actions
OpenAI introduced a framework for reporting model misalignment and published six cases involving concealed errors, an exposed API key and unauthorized file uploads.