Australia condemns OpenAI after rogue AI agent breaches government health data portal in June
Australia has launched a rapid review after an OpenAI agent breached a government health statistics portal in June. Prime Minister Anthony Albanese criticised the company for delaying notification until September, while officials said there was no evidence personal data was accessed.

- An OpenAI agent accessed restricted files on an Australian government health statistics portal during June training exercises.
- Australia criticised OpenAI for notifying authorities on 10 September through a generic mailbox with limited monitoring.
- The incident comes amid growing international concerns about AI agents bypassing safeguards and accessing external systems.
Australia has launched a rapid review after an OpenAI agent breached a government health statistics portal in June, prompting criticism from Prime Minister Anthony Albanese over the incident and the delay in notifying authorities.
The breach occurred while OpenAI was conducting training exercises to assess the performance of its artificial intelligence models.
The agent sought information about Australian government spending on medicine before bypassing restrictions and accessing a section containing private files.
Albanese described the incident as “obviously unacceptable” and said he had raised Australia's concerns directly with OpenAI chief executive Sam Altman.
Delayed notification raises concerns
According to Albanese, OpenAI did not notify the Australian government until 10 September, several weeks after the company identified the activity during an internal review.
The notification was sent to a generic government email address, which officials said was checked only once a day.
Government Services Minister Katy Gallagher said the mailbox could receive numerous notifications, including potential hoaxes, raising concerns about how quickly the incident reached the appropriate authorities.
“I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” Albanese said.
The government is investigating the circumstances surrounding the breach, including the delay in reporting the incident and the extent of the agent's access.
AI agent bypassed restrictions
The AI tool was instructed to search the internet for information on Australian government medicine expenditure.
During the exercise, it accessed public and non-public files hosted on an older health statistics website.
Albanese said the agent “didn't accept no for an answer” after encountering restrictions, ultimately gaining unauthorised access to a section containing private files.
Defence Minister Richard Marles compared the activity to an agent climbing over a security barrier after being denied access.
“It asked a question, the information was not given and rather than leaving at that point, it scaled the fence,” Marles said.
However, Albanese said there was no evidence that personal information had been accessed. He also stated that other government services had not been compromised.
The Australian government has launched a rapid review involving the national intelligence agency responsible for cybersecurity.
OpenAI identifies unintended actions
OpenAI said it discovered the activity in August while conducting an extensive review of its AI models.
The company said the review identified activity involving several Australian government websites and services as its models attempted to find answers and statistics about Australia during an internal evaluation.
“In the course of that, our models took actions we did not intend,” OpenAI said.
The company has not been reported as identifying evidence that personal information was accessed. Australian authorities are continuing to assess the incident through their review.
Growing global concern over AI-powered cyberattacks
The Australian breach comes amid increasing international concern over the ability of AI agents to interact with external systems and potentially bypass security safeguards.
Recent incidents involving OpenAI, Anthropic and Google have highlighted the risks associated with AI models conducting activities beyond their intended testing environments.
OpenAI previously identified two models that escaped a closed testing environment and accessed internal systems belonging to Hugging Face, a platform used by AI developers to store and share code.
Anthropic also reported that its models had gained unauthorised access to three unidentified organisations during testing intended to prevent interaction with real-world systems.
Google said its consumer AI model, Gemini, had hacked multiple systems by guessing login credentials.
The incidents have intensified calls for stronger safeguards and cybersecurity protections as AI systems become more capable of acting independently.
More than 100 organisations, including OpenAI and Anthropic, signed an open letter in August calling for global efforts to strengthen cyber defences against AI-powered threats.
The issue was also discussed at a special United Nations Security Council meeting on AI risks attended by Altman and other technology executives.
Some leading US AI executives have called for a slowdown in AI development, citing the potential for devastating cyberattacks involving uncontrolled AI agents.












