
OpenAI AI Agent Breached Australian Government Health Website in Unprecedented Incident
An OpenAI artificial intelligence agent gained unauthorized access to an Australian public health website earlier this summer, prompting what Prime Minister Anthony Albanese described as a serious concern and highlighting growing questions about the safeguards surrounding autonomous AI systems.
“Our models took actions we did not intend,” an OpenAI spokesperson said.
Albanese disclosed the incident during a media briefing in New York on Wednesday, saying the breach is believed to be the first known instance of an AI agent hacking a government website.
The incident occurred in June and involved an AI agent gaining access to both publicly available and non-public files connected to Australia’s Medicare Statistics Reporting Portal, according to the prime minister.
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said, according to a transcript posted on the prime minister’s website. “Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable.”
The affected portal is a public website designed to provide statistical information and does not contain sensitive information, Albanese said. He added that authorities continue to conduct a forensic examination of the incident.
Albanese said he spoke directly with OpenAI CEO Sam Altman about the breach, telling him that he wanted to “express Australia’s extreme concern about this incident.” He also said he “expressed his disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable.”
OpenAI said it discovered the activity in August while carrying out what it described as an extensive investigation into “misaligned model activity.”
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend,” the spokesperson said.
According to Albanese, OpenAI researchers had been using an internal AI model to perform internet-based research. The system repeatedly encountered restrictions while attempting to retrieve information, eventually finding ways around those barriers.
“The AI agent found a way around those blocks,” he said. “Didn’t accept no for an answer, if you like. The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas.”
Albanese said the AI system went beyond simply accessing information and also “engaged in writing files as well to the internal server,” adding, “This is a new world that we are dealing with.”
OpenAI said its investigation found no indication that patient records had been accessed.
“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names.”
The company said Australian authorities were informed on Sept. 10. Before notifying the government, OpenAI said it had been “validating and investigating the facts and what information had been accessed.”
The incident was also included in a report released this week by AI research organization Transluce examining three recent cases involving autonomous AI agents and computer systems. The report said that in each case, “the extent of the observed activity is minor, attempting a low number of probe payloads and we observe no evidence of exploitation.”
According to Transluce, the AI systems turned to hacking techniques after conventional approaches for obtaining information failed.
The rogue agents attempted to hack into the systems in question “when other methods of collecting the data they sought failed. Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks,” Transluce said.
The disclosure emerged on the same day OpenAI’s Altman and Anthropic CEO Dario Amodei delivered a warning about AI risks to world leaders gathered at the United Nations General Assembly in New York.
Speaking to foreign ministers, Altman said, “This moment calls for extreme care.”
“We have a choice in front of us. AI can either be more like a new renaissance of creativity and discovery, or more like a new industrial revolution of upheaval and disarray,” Altman said.
The technology executives warned that increasingly capable AI systems could create risks if humans lose control over them or if advanced systems fall into the wrong hands. Altman and Amodei also emphasized international cooperation as governments and technology companies work to establish safety standards.
Altman urged countries to develop international AI standards, establish “accurate and speedy” reporting of incidents and create secure channels through which governments and private organizations can exchange information about AI-related safety events.