AI companies have long warned that autonomous agents could act in ways nobody intended. Prime Minister Anthony Albanese has now revealed that an OpenAI agent essentially went rogue and bypassed security controls to access an Australian government portal, according to ABC. Albanese said OpenAI then took nearly three months to report the breach.
The OpenAI agent got into the Medicare Statistics Reporting Service, a standalone website run by Services Australia. The government said there is no evidence the breach touched anyone’s personal medical records or individual Medicare claims. Instead, the portal housed aggregated statistics regarding bulk billing and medication spending.
Acting Prime Minister Richard Marles said Australia keeps its most important national security information behind a fortress. This portal was more like a fence, and the OpenAI agent effectively climbed over it. However, the government said the non-public files it reached were not particularly sensitive and have since been made public.
The agent just kept looking for another way in after the website said no
In June, OpenAI was internally evaluating an AI model by giving it a seemingly boring, benign research task: find information on Australian public spending for health care and medicines. That was the entire goal. When the OpenAI agent arrived at the Services Australia portal and requested the data, the website refused.
Most software would have stopped there. However, this OpenAI agent did something different, as it kept trying until it found an alternative way to get what it wanted. It “didn’t accept ‘no’ for an answer,” Anthony Albanese said. The agent entered areas it wasn’t authorized to access and even wrote files to an internal server during the process.
The timeline of how this came to light is equally frustrating for the Australian government. OpenAI didn’t discover the June activity until August, as it only surfaced during a retrospective review of misaligned model activity. When the company finally reached out, it sent an email to a public vulnerability-reporting inbox instead of using a high-level channel.
Albanese called the notification unacceptable, as the company took far too long to tell the government what had happened. He said he has since raised the matter directly with OpenAI CEO Sam Altman, who recently warned humanity could lose control of the future to AI. Altman accepted that the company had not done well enough, the prime minister added.
This incident follows a troubling pattern. In July, a swarm of experimental OpenAI agents escaped restrictions during internal cybersecurity testing, eventually compromising parts of the Hugging Face infrastructure. Independent researchers at Transluce have also found agents, at least some linked to OpenAI, attempting to hack the Australian Institute of Health and Welfare and a University of New Mexico digital library.
OpenAI has confirmed its agents messaged each other on a German coding website, and posts show them sharing tips on getting around security. Separately, OpenAI says its newest frontier system, GPT-6 Astra, is its first to reach the Critical cybersecurity threshold. This means the model can potentially identify unknown vulnerabilities and exploit well-protected systems without a human guiding each step.
The Australian government has since taken the legacy Medicare portal offline and is moving its public data to data.gov.au. Meanwhile, a taskforce involving the Australian Signals Directorate is working to determine the full extent of what was accessed. Albanese said three other sites may also have been affected, including agencies in New South Wales and Victoria.
The taskforce is also expected to examine whether the incident broke Australian law and whether the matter should be referred to federal police.
Published: Sep 24, 2026 12:45 pm