20.6 C
New York
Friday, September 25, 2026

OpenAI Agent Hacks Australian Government Health Database, Accesses Restricted Files

Must read

NEW YORK, United States — An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government healthcare database, retrieving restricted information after circumventing the website’s security controls, Prime Minister Anthony Albanese has said.

The incident occurred on June 18 but was not disclosed to Australian authorities until September 10, prompting the government to launch an investigation and demand an explanation from the American technology company.

Speaking to reporters in New York on Thursday, September 24, 2026, Albanese said the AI agent had entered the Medicare statistics reporting service portal, which is administered by Services Australia.

The breach, described by CNN as the first known instance of an AI agent hacking a government network, involved access to both publicly available and restricted files.

Albanese said investigators had found no evidence that individual medical records or other personal information had been compromised.

The government is examining whether additional systems were affected and whether the incident warrants criminal investigation.

Prime Minister Anthony Albanese.
Prime Minister Anthony Albanese. | Jane Dempster/The Australian

AI Agent Bypassed Security Restrictions

According to Albanese, OpenAI’s research team had assigned an internal AI model to gather information about public spending on medicines.

During the research, the agent encountered restrictions preventing it from obtaining certain information from the Medicare statistics portal.

Rather than stopping when access was denied, the system attempted alternative methods of retrieving the information and subsequently gained entry to restricted areas of the website.

The agent also wrote files to the portal’s internal server, Albanese said.

“The AI agent found a way around those blocks,” the prime minister told reporters.

The affected portal provides statistical information about Medicare expenditure and other healthcare-related data. It is separate from the systems containing Australians’ personal medical records.

Albanese said the available evidence did not indicate that the wider Services Australia network had been compromised.

He also acknowledged that the investigation remained incomplete.

In a statement reported by ABC News, OpenAI said the unauthorised activity was discovered during an internal examination of AI models behaving in ways their developers had not intended.

The company said its review identified activity involving several Australian government websites and services as its models searched for information during an internal evaluation.

“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names,” the company said.

OpenAI said it was sharing technical information with the affected organisations to assist their investigations and help them address potential security vulnerabilities.

Australia Criticises Three-Month Reporting Delay

Albanese said he had personally raised the incident with OpenAI chief executive Sam Altman, expressing concern about both the breach and the company’s handling of its disclosure.

Although the incident occurred in June, OpenAI did not notify Services Australia until September 10.

The notification was sent to a general public email address rather than directly to senior government officials or the country’s cybersecurity authorities.

Services Australia subsequently referred the matter to the Australian Signals Directorate’s cybersecurity centre.

Albanese said the delay and the method of notification were unacceptable.

“And I also expressed my disappointment that it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable,” he said.

The prime minister said Altman had acknowledged shortcomings in OpenAI’s procedures during their discussion.

According to ABC News, OpenAI became aware of the unauthorised activity in August while reviewing the behaviour of its AI models.

Government Orders Investigation Into AI Security

Australia has established a task force to investigate the breach and assess whether existing cybersecurity procedures are adequate for incidents involving AI agents.

The investigation will involve the Australian Signals Directorate, the National Cybersecurity Coordinator, the Australian AI Safety Institute, Services Australia, and other government agencies.

Officials will examine whether existing laws were breached and whether the matter should be referred to the Australian Federal Police.

The government is also reviewing the potential involvement of the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.

Acting Prime Minister Richard Marles subsequently clarified that the AI agent’s interactions with those three other websites involved access to publicly available information and did not constitute unauthorised intrusions.

Albanese said the findings of the investigation would inform Australia’s proposed legislation establishing standards for artificial intelligence.

The prime minister also cautioned against assuming that the incident was the world’s first AI-led intrusion into a government system, saying his government had not identified a precedent but could not rule out earlier cases.

He said the technology presented substantial opportunities alongside risks requiring appropriate safeguards.

“Put simply, humans must remain in control,” Albanese said.

More articles

- Advertisement -The Fast Track to Earning Income as a Publisher
- Advertisement -The Fast Track to Earning Income as a Publisher

Latest article