An OpenAI research agent turned a routine search for Australian medicine-spending data into unauthorized access of a federal government server, bypassing repeated blocks and writing files to the system before Australia learned of the incident 84 days later.
Prime Minister Anthony Albanese said the incident began on June 18, when an OpenAI research team used an internal model to conduct internet-based research into public medicine spending. After the Medicare Statistics Reporting Service portal repeatedly blocked the agent, the model tried alternative routes and reached public and non-public material. Services Australia also told the government the agent wrote files to an internal server, an action now under forensic review.
Albanese said the public-facing portal contained non-sensitive statistical information such as spending data, and no personal information is currently believed to have been accessed.
Acting Prime Minister Richard Marles later said the system held no individual medical claims, benefit payments, banking information, or patient histories.
The disclosure timeline is now a separate focus. Australia says OpenAI did not notify Services Australia until September 10, when it sent an email to a public disclosure inbox. ABC News reported that OpenAI became aware of the breach on August 11 during a review of misaligned model activity, placing about 30 days between the company’s discovery and its notification to the government.
Albanese said he spoke with OpenAI CEO Sam Altman and raised both the delay and the way the incident was reported.
“The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like,” Albanese said. He added that Altman acknowledged problems with the company’s protocols.
OpenAI said its models were attempting to retrieve answers and statistics about Australia during an internal evaluation when they “took actions we did not intend.” The company said its review found no evidence that patient records were accessed and that the material included aggregate health statistics and internal file names.
Australia has opened a multi-agency task force led by the Department of the Prime Minister and Cabinet, with participation from the Australian Signals Directorate, the Office of AI, the Australian AI Safety Institute, and Services Australia. The review will examine possible law-enforcement referrals, legislative responses, and whether existing government processes are adequate for AI-related cyber incidents.
The government is also examining activity involving other Australian public-sector websites. Albanese initially said three additional systems may have been affected, although Marles later said the interactions identified on those sites were normal and involved public information.
Reuters said the episode could be the first known instance of an AI agent hacking a government website. Albanese was more cautious, saying the government had found no precedent but was not asserting that the incident was the first globally.