An artificial intelligence agent operated by OpenAI reportedly accessed an Australian government website in June and gained unauthorized access to several files, prompting concern among Australian authorities.
Australian Prime Minister Anthony Albanese described the incident as “unacceptable,” while experts cited by the BBC said it could represent the first publicly known case of an AI agent breaching a government system.
According to Albanese, the OpenAI agent accessed publicly available, non-statistical data related to Australia’s Medicare insurance program as part of research examining public healthcare spending.
The Australian prime minister said OpenAI notified the government about the incident only in September. He added that investigations were still underway and that he had expressed his “extreme concern about the incident” directly to OpenAI CEO Sam Altman.
Albanese also warned that the AI agent’s activity may have affected three other government websites connected to public health, although this has not been confirmed.
OpenAI acknowledged that its agents had targeted several Australian government websites and services, but said the company identified the activity in August.
“We identified activity involving a number of Australian government websites and services, where our models were attempting to retrieve answers,” the company said in a statement.
OpenAI added that its models took actions the company had not anticipated, but said its investigation found no evidence that the agents accessed patients’ medical records.
The Australian government has established a task force to investigate the incident and assess whether existing network-security measures are sufficient to prevent similar incidents in the future.
The incident comes amid growing concern over the use of autonomous AI agents and their ability to interact with external systems. OpenAI’s own documentation describes agents as systems capable of independently carrying out tasks using tools within defined safeguards, while also warning that agentic systems can face risks such as prompt injection and unintended actions.
OpenAI has also acknowledged that increasingly capable AI systems are creating new cybersecurity risks, including the potential for models to enable attacks at greater speed and scale.
Similar cases involving AI agents gaining access to external systems have reportedly raised concerns across the technology industry, including around systems developed by other major technology companies.
The Australian incident is likely to intensify the debate over how governments should regulate and secure autonomous AI systems, particularly when they are capable of navigating websites, using tools and taking actions with limited human intervention.
