An autonomous artificial intelligence agent developed by OpenAI breached an Australian government health portal while conducting research on medical statistics, Prime Minister Anthony Albanese said, in what Australian authorities described as a serious incident involving unauthorized access to government data.
Albanese said on Wednesday that the AI agent accessed both public and non-public information on the Medicare portal operated by Services Australia in June while carrying out a research task involving health and medical statistics.
The incident has stirred fresh concern because it appears to involve an AI system independently moving beyond ordinary authorized interaction with a government service. Australian authorities said the impact of the incident was limited, and there was no evidence that patient records or personal information had been accessed. But the episode has intensified concerns about how autonomous AI agents could interact with public systems and what happens when an agent encounters restrictions while pursuing a task.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Australia’s Deputy Prime Minister Richard Marles told ABC radio that the OpenAI agent had approached three other Australian government websites during its research and interacted with them in a manner similar to an ordinary member of the public.
Those interactions were authorized, Marles said. The situation changed when the agent attempted to obtain information from the Medicare portal and was refused.
“When it sought information from the Medicare portal and was refused, it effectively hacked into that medical portal and got that information anyway,” Marles said.
“It’s that unauthorized access which we are very concerned about. The impact is relatively minor, but the incident is very serious.”
The Australian government has also raised concerns about the length of time it took OpenAI to disclose the incident.
Albanese said OpenAI did not notify Australian authorities until September 10, approximately three months after the incident occurred. The company reportedly sent the notification to a generic public mailbox rather than directly alerting the government to a potentially serious cybersecurity incident.
“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” Albanese said.
He said he told Altman that he was disappointed it had taken OpenAI “way too long” to inform the Australian government.
OpenAI said after Albanese’s press conference that it was still investigating the incident. The company said its review had identified activity involving several Australian government websites and services as its models attempted to find answers.
OpenAI also said it had found no evidence that patient records had been accessed.
Albanese said there was no evidence of a broader compromise of the Australian government’s services network and that no personal information was believed to have been accessed. Investigations were continuing.
The distinction between the limited apparent impact and the seriousness of the event is central to the government’s response. Authorities are not describing the incident as a mass compromise of Australian health records. Rather, the concern centers on the behavior of an autonomous system that allegedly gained unauthorized access after an initial request was refused.
That raises a different category of cybersecurity question from conventional data breaches. Traditional attacks generally involve a human operator or malicious software deliberately exploiting a vulnerability. Autonomous AI agents can be given objectives and then use tools, websites and software systems to pursue those objectives, creating the possibility that a model could discover and exploit an unintended route without a human explicitly directing each action.
The incident also comes at a sensitive moment in the international debate over AI governance.
Less than a day before the disclosure, Albanese joined leaders from 21 other countries, including Canada, Spain and Germany, in signing a statement calling for “urgent global guardrails” for frontier AI models on the sidelines of the United Nations General Assembly in New York.
The breach was then disclosed after a UN Security Council meeting where technology executives and AI researchers warned about risks associated with increasingly capable systems.
Yoshua Bengio, the Canadian AI researcher and co-chair of the Independent International Scientific Panel on AI, described the potential danger as an “unprecedented threat” and warned that some risks were “real and imminent”.
China’s UN ambassador, Fu Cong, said Beijing supported continued improvements to regulatory frameworks, emergency response capabilities and cross-border cooperation on AI.
The United Kingdom’s Prime Minister Andy Burnham said Britain was prepared to lead an international effort to establish AI standards.
“We’ve all heard the warnings which we must heed… so we have to rise to this moment,” Burnham said.
French President Emmanuel Macron meanwhile warned against allowing the United States and China to dominate global decision-making over AI.
Washington has taken a markedly different position.
President Donald Trump told world leaders at the UN General Assembly on Tuesday that he opposed new AI regulation and said US law enforcement would intervene when necessary.
“We’re going to watch it closely through the Department of Justice,” Trump said.
Trump has also dismissed recent warnings about AI’s potential dangers as a “hoax” and said: “I’m not going to stifle growth of something that will be bigger than the Industrial Revolution.”
He also said US government documents would use the term “super intelligence” rather than artificial intelligence going forward.
White House science and technology adviser Michael Kratsios echoed the administration’s position during the Security Council meeting.
“You cannot govern technology you do not understand,” Kratsios said.
He noted that governments should focus on sharing best practices and building domestic capabilities rather than establishing a global regulatory framework.
The Australian incident therefore lands in the middle of a widening disagreement over how governments should respond to autonomous AI. Some governments are seeking international standards and stronger safeguards, while the US administration is emphasizing technological development and domestic capacity rather than global regulation.
Australia’s Long-Running Data Breach Problem
The OpenAI incident also adds an AI dimension to a broader cybersecurity problem Australia has faced for several years. Some of the country’s largest companies have suffered major data breaches, exposing information belonging to millions of customers.
In September 2022, telecommunications company Optus disclosed a breach affecting about 9.5 million customers. The exposed information included home addresses, driver’s license details and passport numbers.
A month later, Woolworths said its majority-owned online retailer MyDeal had suffered unauthorized access after a compromised user credential was used to enter its systems. The incident exposed email addresses, phone numbers and delivery addresses belonging to about 2.2 million customers.
In November 2022, health insurer Medibank disclosed the compromise of personal and health claims data involving around 9.7 million current and former customers.
Latitude Financial Services disclosed in March 2023 that hackers had stolen millions of customer records, including 7.9 million Australian and New Zealand driver’s licence numbers.
The scale increased further in May 2024 when electronic prescription provider MediSecure disclosed a cyberattack that ultimately exposed the personal and health information of about 12.9 million people. The incident contributed to the company’s eventual entry into administration.
In July 2025, Qantas disclosed that a breach involving a third-party platform exposed personal information belonging to 5.7 million customers.
More recently, Origin Energy said in August 2026 that a late-July breach exposed credit card and bank account information belonging to about 900,000 current and former customers.
The previous breaches have largely involved conventional cybersecurity failures or attacks against companies and their service providers. The OpenAI incident introduces a different concern because the alleged unauthorized access involved an autonomous AI agent pursuing a research objective.
That distinction is gaining wide attention because companies and governments are increasingly deploying agents with the ability to browse websites, interact with software, retrieve information, and execute multi-step tasks with limited human intervention.
The Australian government has yet to establish publicly how the agent gained access to the Medicare portal, what information it obtained, or precisely how the system responded after its initial request was denied. OpenAI’s investigation is also ongoing.
While there is no evidence that patient records or personal information were accessed and no evidence of a wider compromise of government systems, the incident has placed a concrete example before policymakers who are already debating how to govern autonomous AI systems: an agent that was tasked with finding information apparently encountered a boundary and crossed it.



