Australia says OpenAI agent breached government health data portal
An OpenAI artificial intelligence agent gained unauthorised access to an Australian government health data portal in June, Prime Minister Anthony Albanese said on Wednesday, describing the incident as unacceptable and raising concerns about how government systems failed to detect the activity.
The breach, which affected a portal containing non-sensitive health statistics and public medical spending data, is believed to be among the first known cases of an AI agent independently accessing a government website without authorisation.advertisement❮❯ Read Full StoryGOVERNMENT PROBES EXTENT OF ACCESSSpeaking in New York during the UN General Assembly, Albanese said investigations were continuing but stressed there was no evidence so far of a broader compromise of government networks.
“Evidence currently available is there is no broader compromise to the network. Nonetheless, this situation is obviously unacceptable,” he said.
Albanese said Australia had conveyed its “extreme concern” directly to OpenAI chief executive Sam Altman and criticised the company for the delay in informing authorities about the incident.
According to the prime minister, the government was not notified until September 10, more than two months after the activity occurred.
The investigation will also examine whether shortcomings in government cybersecurity systems contributed to the failure to detect the unauthorised access earlier.THREE GOVERNMENT SITES UNDER REVIEW
Authorities are also assessing whether the AI agent interacted with additional government platforms.
Albanese said three other government websites may have been affected, although investigators have not established whether any data was accessed.
“The question is, when it was trying to harvest data, did it go into these other sites? So we're not confirming that that occurred,” he said.OPENAI SAYS NO PATIENT RECORDS ACCESSED
OpenAI said its review found no indication that patient records or sensitive personal information were accessed.
According to the company, the material involved aggregate health statistics and internal file names.
The company said it identified activity involving several Australian government websites while its AI models were attempting to retrieve information.
“Our models took actions we did not intend,” OpenAI said, adding that the systems had been trying to look up answers across external websites and services.LATEST IN A SERIES OF AI AGENT INCIDENTS
The Australian case adds to growing scrutiny of AI agents capable of independently interacting with external systems.
It follows several recent incidents worldwide involving AI tools accessing websites, repositories and online services in unexpected ways, prompting concerns among governments, regulators and businesses about the risks posed by increasingly autonomous systems.
OpenAI has previously disclosed cases involving unauthorised or unexpected activity by its AI agents, some of which were reported weeks after they occurred. One widely discussed incident involved an intrusion into the open-source AI platform Hugging Face in July, which was detected only after a delay.
Other major AI developers, including Anthropic, Google and Meta, have also reported instances in which their AI systems interacted with external platforms in unintended ways.
The incidents have intensified debate over AI safety and oversight, with several industry leaders — including Altman — warning that increasingly powerful AI agents could pose cybersecurity risks if not properly controlled.DEBATE OVER AI REGULATION
The disclosure comes as AI companies and governments continue to debate the regulation of advanced AI systems.
Earlier this month, OpenAI and Anthropic urged an Australian parliamentary inquiry to reconsider restrictions on the use of Australian creative content for training AI models, arguing that broader access to data would support innovation and competitiveness.
The latest breach is likely to add momentum to discussions over how AI agents should be monitored, governed and prevented from accessing systems without authorisation.- EndsWith inputs from ReutersPublished By: Nitish SinghPublished On: Sep 24, 2026 06:40 IST

