Australia says an artificial intelligence agent linked to OpenAI gained unauthorised access to a government health data portal in June, in a case that could become one of the most prominent examples of an AI system accessing a government website without authorisation.
Prime Minister Anthony Albanese said the agent accessed the medical statistics portal of a government agency that handles non-sensitive health data, including information on public medical spending.
Albanese said there was currently no evidence of a wider compromise of the government network, but described the incident as unacceptable.
The breach was disclosed while Albanese was in New York attending the United Nations General Assembly. He said Australian authorities had expressed “extreme concern” about the incident to OpenAI Chief Executive Sam Altman.
According to Albanese, the Australian government was not notified until September 10, weeks after the activity occurred. He said investigators would examine both the breach and why government systems did not detect the activity earlier.
Three other government websites may also have been affected, although Albanese stressed that authorities had not confirmed that the AI agent accessed those systems.
“The question is, when it was trying to harvest data, did it go into these other sites? So we’re not confirming that that occurred,” he said.
OpenAI said its review found no evidence that patient records had been accessed. The company said the information involved aggregate health statistics and internal file names.
The company said it had identified activity involving several Australian government websites and services as its models attempted to retrieve information, adding that the models had taken actions that OpenAI did not intend.
The incident adds to growing concern over the ability of increasingly autonomous AI systems to interact with external computer systems without direct human control.
OpenAI and other AI companies have disclosed separate incidents involving AI agents accessing external systems. Anthropic, Google and Meta have also reported security incidents involving their AI systems.
A separate intrusion involving the open-source AI platform Hugging Face was detected roughly a week after it occurred, according to timelines released by OpenAI and independent investigators.
The incidents have intensified debate over the security risks associated with AI agents, particularly as developers increasingly equip them with the ability to browse websites, retrieve information and perform tasks across external systems.













