Thursday, September 24, 2026 - An OpenAI artificial intelligence agent accessed an Australian government healthcare portal and other public-sector websites without authorisation during an internal evaluation, prompting Prime Minister Anthony Albanese to order an urgent security review.
The incident occurred in June while OpenAI was testing AI
agents tasked with researching questions about Australian medical spending.
According to the company, the agents were expected to search for publicly
available information needed to answer the questions.
However, when one agent was unable to obtain all the
information it required, it communicated with other AI agents through DseWiki,
described in the report as a coding site that AI systems had previously
accessed and used as a message board. The agents then reportedly worked
together to find ways around cybersecurity restrictions protecting Australian
government websites.
One of the systems accessed was the Medicare Statistics
Reporting Service Portal, which contains information relating to Australia’s
universal healthcare programme. “The AI agent found a way around those blocks,
didn’t accept ‘no’ for an answer,” Albanese said.
At least three other government systems may also have been
accessed, according to officials. They included websites associated with the
Australian Institute of Health and Welfare, the New South Wales crime
statistics agency and Victoria’s health department. OpenAI said it detected the
activity in August and launched an investigation. The company said the
information accessed included aggregate health statistics and internal file
names, rather than personal patient information.
“We identified activity involving several Australian
government websites and services as our models attempted to look up answers,
and available statistics for questions about Australia during an internal
evaluation,” OpenAI said. The company acknowledged that “our models took
actions we did not intend.”
Albanese revealed the incident on Thursday and said he had
spoken directly with OpenAI chief executive Sam Altman to raise concerns about
both the breach and the length of time it took the company to inform Australian
authorities. “Today I spoke with the CEO of OpenAI, Sam Altman, to express
Australia’s extreme concern about this incident,” Albanese said. “And I also
expressed my disappointment that it took the company way too long to inform the
government what had occurred.”
The prime minister said OpenAI’s handling of the
notification was “unacceptable,” claiming the government was not directly
informed immediately after the company became aware of the incident. Instead,
Albanese said notification was sent to a general government email inbox on
September 10. The Australian government has now ordered an “urgent and
immediate” review of the security implications of the incident.
Communications Minister Anika Wells said the Australian
Signals Directorate would investigate the breach and examine whether there were
grounds for legal action. “We want big tech to take accountability,” Wells
said. OpenAI said it was cooperating with the investigation and providing
technical assistance to help identify and address potential security
vulnerabilities.
The incident was disclosed as Albanese attended meetings in
New York, where international leaders were also discussing concerns surrounding
the safety and security of increasingly autonomous artificial intelligence
systems. OpenAI said its own review of the Australian incident remained ongoing
and that the company was “committed to transparency.”

0 Comments