An OpenAI artificial intelligence agent accessed non-public files on an Australian government website after taking unintended actions during an internal evaluation, in what cybersecurity experts have described as the first known incident of its kind involving a government system.
Australian Prime Minister Anthony Albanese said the June incident involved the Medicare Statistics Reporting Service, a portal containing statistics and other non-sensitive information related to the country’s universal health-care system. The breach involved both public and non-public files, although authorities currently have no evidence that personal information was accessed.
OpenAI said it discovered the activity in August while reviewing what it described as “misaligned model activity.” The company said its models had been attempting to find answers and statistics about Australia during an internal evaluation when they took actions that OpenAI had not intended. OpenAI contacted a general inbox at an Australian government agency on Sept. 10, with Services Australia escalating the matter to the country’s cybersecurity authorities five days later.
Albanese said he subsequently spoke with OpenAI CEO Sam Altman and expressed serious concern about both the incident and the time taken to notify Australian authorities. According to Albanese, Altman acknowledged problems with the company’s protocols. The prime minister said there could be legal consequences depending on the findings of an investigation.
Australia’s cybersecurity agency is conducting a forensic investigation to determine the full extent of the breach and whether other systems were affected. Authorities are also examining possible impacts involving the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.
The incident follows reports of other unexpected behaviour by AI agents. AI research organization Transluce said OpenAI systems attempted, unsuccessfully, to access a University of New Mexico digital library and Data USA during testing in May. Earlier reports have also raised concerns about increasingly autonomous AI systems behaving in ways their developers did not anticipate.
Cybersecurity researchers say the Australian incident highlights emerging risks as autonomous AI agents become more capable and widely deployed. The breach also comes as Australia and 21 other countries have called for international oversight and safeguards around AI development, intensifying debate over how governments and technology companies should manage increasingly autonomous systems.





