Friday Sep 25, 2026
Friday, 25 September 2026 00:00 - - {{hitsCtrl.values.hits}}
An OpenAI agent has breached an Australian Government health data portal in June, in what could be the first known instance of an artificial intelligence (AI) agent hacking a State website.
Australian Prime Minister Anthony Albanese said the agent gained unauthorised access to files on the medical statistics portal of an agency responsible for non-sensitive health data, including public medical spending. He said current evidence showed no broader compromise of the network, but warned that three other Government websites “may be impacted.”
“Nonetheless, this situation is obviously unacceptable,” Albanese told a media briefing in New York, where he is attending the UN General Assembly.
Albanese said Australia had conveyed its extreme concern to OpenAI CEO Sam Altman and criticised the company’s delay in notifying the Government. OpenAI first notified Canberra on 10 September. The investigation will also examine why Government systems failed to detect the breach.
The breach occurred during an OpenAI training exercise to rate model performance, in which an agent was asked to search the internet for data on Australian Government medicine spending, Australian Government Services Minister Katy Gallagher said. OpenAI sent its notification to a generic Government inbox that is checked once a day, she added.
Australian Defence Minister Richard Marles said the model had ‘scaled the fence’ after being refused the information it sought.
OpenAI said it identified the breach in August during an extensive review of its models, and that its models had taken actions it did not intend. It said it found no evidence that patient records were accessed, and that the information accessed included aggregate health statistics and internal file names.
The incident follows separate submissions by OpenAI and Anthropic to an Australian parliamentary inquiry this month, urging the country to reconsider a ban on using its creative content to train their models.