Info Gov

The Australian government has confirmed what is understood to be the first case of an artificial intelligence agent breaching a government system without being instructed to do so, after an autonomous OpenAI agent bypassed access controls on the Medicare Statistics Reporting Service portal run by Services Australia while carrying out a research task.

Australia's Prime Minister Anthony Albanese said the agent had been set a task on public medicines spending during an internal capability evaluation by OpenAI. It located the portal while searching the internet, was refused access and, in his words, "found a way around those blocks, didn't accept 'no' for an answer, if you like". He described the incident as "real and serious" and one that "had been predicted, including by the AI companies themselves".

No human at OpenAI directed the agent to access the system. OpenAI spokesperson Drew Pusateri said the company had identified "activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation", adding: "In the course of that, our models took actions we did not intend."

The breach occurred on 18 June 2026. OpenAI identified the activity in August while reviewing what it described as misaligned model behaviour, but did not notify Services Australia until 10 September, when it emailed a public mailbox that is checked once a day.

The agency saw the message on 11 September, confirmed it was legitimate and escalated it to the Australian Signals Directorate on 15 September, with the Government Services Minister, Katy Gallagher, informed on 17 September. The incident was made public on 24 September.

The case is significant because of how the information was taken rather than what was taken. The portal holds aggregate data including bulk billing figures, immunisation statistics, Pharmaceutical Benefits Scheme data, organ donor registry statistics and annual reports.

Albanese said the agent "accessed both public and non-public files", but that no personal information is believed to have been accessed and the non-public material has since been published. OpenAI said its review "found no evidence of patient records being accessed" and that the information obtained "included aggregate health statistics and internal file names". Deputy Prime Minister Richard Marles said the impact was "relatively minor" and that "no personal information has been accessed here".

Marles said the government kept its most important national security information "behind a fortress", whereas the statistics portal "was really kept behind a fence that the AI agent effectively climbed over". The same agent also interacted with the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health, but Marles said those interactions were "entirely normal" and involved only public information.

A taskforce led by the Department of the Prime Minister and Cabinet, involving the Australian Signals Directorate, the AI Safety Institute and the Office of AI, is examining "whether what occurred was legal" and whether penalties are available, Marles said, and will also review how government systems interact with external AI platforms more generally.

In the UK, an equivalent incident would engage the security obligations on controllers under Article 32 of the UK GDPR and, where personal data was involved, the 72-hour breach notification requirement under Article 33, while the Computer Misuse Act 1990 turns on unauthorised access rather than on whether the actor is a person or a machine.

Albanese said he had spoken to OpenAI chief executive Sam Altman to "express Australia's extreme concern about this incident" and his "disappointment that it took the company way too long to inform the government what had occurred". Asked whether Altman had accepted responsibility, Albanese said: "We can get into word games, but he clearly accepted that the company had not done good enough."

The Australian Cyber Security Centre has issued guidance to organisations on the risks posed by AI agents, recommending stronger authentication safeguards, continuous patching and incident response arrangements that anticipate automated rather than human actors. A forensic investigation into both the breach and the notification delay is under way.

The Australian Cyber Security Centre's guidance on AI agent risks is available at cyber.gov.au.

Also in this section

Sep 25, 2026

NHS England orders immediate suspension for staff suspected of snooping on patient records

NHS England has instructed every trust in England to suspend immediately any member of staff suspected of accessing patient records without a legitimate reason and to remove their access to NHS systems while the facts are established, in a letter from chief executive Sir Jim Mackey announcing a zero-tolerance approach to what he called snooping.
Sep 23, 2026

Prime Minister announces new National Centre for Information Defence

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.
Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.

InfoGov Masthead Newsletter 800