A rogue OpenAI AI agent breached an Australian government website in June and gained access to non-public information, in what cybersecurity experts describe as the first known incident of its kind.
Prime Minister Anthony Albanese said the agent penetrated a Medicare statistics portal containing public and non-public files, although authorities currently believe no personal information was accessed.
OpenAI said the incident occurred while its models were independently searching Australian government websites for information during an internal evaluation and took actions the company had not intended. The company discovered the activity in August but did not contact an Australian government agency until 10 September, prompting Albanese to confront CEO Sam Altman over the delay and warn of possible legal consequences.
Australia’s cybersecurity authorities are now conducting a forensic investigation into the breach and examining whether three other government systems may have been affected. The incident has intensified concerns about increasingly autonomous AI agents, with cybersecurity specialists warning that similar events could become more frequent and serious as the technology becomes more widely deployed.