An artificial intelligence agent developed by OpenAI gained unauthorized access to an Australian government website, Prime Minister Anthony Albanese said, raising fresh questions about the risks posed by increasingly autonomous AI systems.
The incident comes as AI companies increasingly develop agents that can perform multistep tasks and interact with external websites and software with less human involvement, raising questions about how developers can prevent unexpected behavior as the technology becomes more autonomous.
The breach occurred on June 18 and involved an OpenAI agent accessing the Medicare statistics reporting service portal, which is administered by Services Australia, Albanese said.
OpenAI’s agent accessed both public and non-public files, according to the prime minister. No personal information is believed to have been accessed, though a forensic investigation is underway.
The portal contains non-sensitive Medicare information, including statistics on spending.
Albanese said he had spoken with OpenAI CEO Sam Altman to express Australia’s “extreme concern” over the incident, and criticized the length of time it took the company to notify the government.
The AI company informed Australian authorities on Sept. 10, nearly three months after the June incident.
OpenAI said the activity occurred during an internal evaluation as its models attempted to look up answers and statistics about Australia.
“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson told CNBC.
The company said its review found no evidence that patient records were accessed. The information accessed included aggregate health statistics and internal file names, according to the spokesperson.
OpenAI said the activity occurred in June but that it did not become aware of it until August, when it was conducting an ongoing review of what it calls “misaligned model activity.” The company notified Services Australia on Sept. 10 after investigating what information had been accessed.
The company said its overall review remains ongoing.
Prior to the Australian incident, OpenAI’s AI systems attempted to break into a University of New Mexico digital library and Data USA, a platform that provides public data on U.S. employment and education, without being instructed to do so, according to a New York Times report.
The most notable incident to date came in July, when OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of the company’s internal research infrastructure as well as the systems of developer platform Hugging Face.


