The Australian government has confirmed what is understood to be the first case of an artificial intelligence agent breaching a government system without being instructed to do so, after an autonomous OpenAI agent bypassed access controls on the Medicare Statistics Reporting Service portal run by Services Australia while carrying out a research task.
Australia's Prime Minister Anthony Albanese said the agent had been set a task on public medicines spending during an internal capability evaluation by OpenAI. It located the portal while searching the internet, was refused access and, in his words, "found a way around those blocks, didn't accept 'no' for an answer, if you like". He described the incident as "real and serious" and one that "had been predicted, including by the AI companies themselves".
No human at OpenAI directed the agent to access the system. OpenAI spokesperson Drew Pusateri said the company had identified "activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation", adding: "In the course of that, our models took actions we did not intend."
The breach occurred on 18 June 2026. OpenAI identified the activity in August while reviewing what it described as misaligned model behaviour, but did not notify Services Australia until 10 September, when it emailed a public mailbox that is checked once a day.
The agency saw the message on 11 September, confirmed it was legitimate and escalated it to the Australian Signals Directorate on 15 September, with the Government Services Minister, Katy Gallagher, informed on 17 September. The incident was made public on 24 September.
The case is significant because of how the information was taken rather than what was taken. The portal holds aggregate data including bulk billing figures, immunisation statistics, Pharmaceutical Benefits Scheme data, organ donor registry statistics and annual reports.
Albanese said the agent "accessed both public and non-public files", but that no personal information is believed to have been accessed and the non-public material has since been published. OpenAI said its review "found no evidence of patient records being accessed" and that the information obtained "included aggregate health statistics and internal file names". Deputy Prime Minister Richard Marles said the impact was "relatively minor" and that "no personal information has been accessed here".
Marles said the government kept its most important national security information "behind a fortress", whereas the statistics portal "was really kept behind a fence that the AI agent effectively climbed over". The same agent also interacted with the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health, but Marles said those interactions were "entirely normal" and involved only public information.
A taskforce led by the Department of the Prime Minister and Cabinet, involving the Australian Signals Directorate, the AI Safety Institute and the Office of AI, is examining "whether what occurred was legal" and whether penalties are available, Marles said, and will also review how government systems interact with external AI platforms more generally.
In the UK, an equivalent incident would engage the security obligations on controllers under Article 32 of the UK GDPR and, where personal data was involved, the 72-hour breach notification requirement under Article 33, while the Computer Misuse Act 1990 turns on unauthorised access rather than on whether the actor is a person or a machine.
Albanese said he had spoken to OpenAI chief executive Sam Altman to "express Australia's extreme concern about this incident" and his "disappointment that it took the company way too long to inform the government what had occurred". Asked whether Altman had accepted responsibility, Albanese said: "We can get into word games, but he clearly accepted that the company had not done good enough."
The Australian Cyber Security Centre has issued guidance to organisations on the risks posed by AI agents, recommending stronger authentication safeguards, continuous patching and incident response arrangements that anticipate automated rather than human actors. A forensic investigation into both the breach and the notification delay is under way.
The Australian Cyber Security Centre's guidance on AI agent risks is available at cyber.gov.au.

