News

OpenAI AI Agent Accessed Australian Government Health Portal in June

An OpenAI AI agent accessed public and non-public files on an Australian government health portal in June. Authorities discovered the incident in August and were notified in September.

Written By : Somatirtha
Reviewed By : Pranchal Srivastava

An OpenAI AI agent gained unauthorized access to an Australian government Medicare statistics portal in June while being evaluated for training, accessing public and non-public files, the Australian Prime Minister, Anthony Albanese, said. The government said there is no evidence that personal Medicare data was accessed.

AI Agent Bypassed Restrictions

The incident took place on June 18, when OpenAI's research team used an internal model to conduct internet-based research into Australian government spending on medicines. The AI agent interacted with several government websites during the task.

On the Medicare statistics portal, the agent encountered restrictions but continued trying to obtain the information. Albanese said the model found a way around the blocks and subsequently accessed public and non-public information.

The material included non-public aggregate health statistics and internal file names. Services Australia also said the agent wrote files to an internal server, an aspect that remains under investigation. OpenAI said there was no evidence that patient records were accessed.

Also Read: OpenAI May Preview GPT-6 Cyber on September 29: What to Know

OpenAI Discovered Incident in August

OpenAI did not identify the activity immediately. According to the Australian government, the company discovered the incident on August 11 while reviewing potentially misaligned model activity during training.

OpenAI said it identified activity involving several Australian government websites and services while its models were attempting to find answers and available statistics about Australia during an internal evaluation. The company said its models took actions it did not intend.

Government Notified Nearly a Month Later

Although OpenAI identified the incident in August, Australian authorities were notified on September 10. The company emailed a public Services Australia mailbox used by academics and researchers to report potential weaknesses.

Services Australia reviewed the message before notifying Australia's cyber security agency, the Australian Signals Directorate, on September 15. Albanese criticized both the delay and how the incident was reported.

Albanese Spoke with Sam Altman

Albanese said he spoke with OpenAI CEO Sam Altman to express Australia's concern about the incident and the delay in notification. The Australian government has launched a rapid review involving the Prime Minister's Department, Australian Signals Directorate, Office of AI, Australian AI Safety Institute and Services Australia.

The review will examine the incident and whether existing government processes adequately address security incidents involving autonomous AI systems. A forensic investigation is also underway to determine whether other government systems were affected.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

How Bitcoin Technical Analysis Works

How Solana is Powering Tokenized Stocks

Next Big Cryptos in 2026 That Could Trigger the Market’s Next Major Breakout: BlockDAG, Sui, Cardano & Stellar

Hive Challenges Sweden Over Bitcoin Mining VAT Rules

Bitget Suspects North Korean Hackers in $351.6M Security Breach