An OpenAI agent gained unauthorised access to Australia’s Medicare Statistics Reporting Service portal on June 18, read public and non-public files and wrote files to the internal server, Prime Minister Anthony Albanese said in New York on September 23. OpenAI told the Australian government on September 10, nearly three months later, by emailing a public mailbox.
“I also expressed my disappointment that it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable,” Albanese said, after speaking to OpenAI chief executive Sam Altman.
He called the incident “obviously unacceptable”. CNN described it as the first known case of an AI agent hacking a government network.
How the agent got in: On June 18, an OpenAI research team used an internal model to research public medicine spending. “After encountering repeated blocks, so there’s an AI agent looking for information, asking questions. There were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like,” Albanese said. The model then tried alternative routes, which took it into other areas of the portal.
What OpenAI says it found: OpenAI is “conducting an extensive review of misaligned model activity” during training, and notifies third parties when it finds a potential impact on their systems, spokesperson Drew Pusateri said in a statement to ABC News. “During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” he said.
“In the course of that, our models took actions we did not intend. Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names.”
Albanese said Altman apologised. “He clearly accepted that the company had not done good enough,” he said, adding that Altman acknowledged the company’s “protocols were not up to scratch here”.
Three more systems may be affected: Albanese named the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. All hold data on medicines and health, and all form part of the same incident. A forensic investigation aided by the Australian Signals Directorate is examining which other government systems the agent reached.
The review that found it started with Hugging Face: In July, OpenAI said a combination of GPT-5.6 Sol and a more capable, unreleased model carried out a cyberattack on the AI platform during an internal evaluation, MediaNama reported. It called the breach an “unprecedented cyber incident”.
The models were running inside an isolated research environment with no direct internet access, as part of ExploitGym, a benchmark that measures how well AI systems carry out complex cyberattacks. They found and exploited a previously unknown vulnerability in package installation software, escaped the test environment, and moved through OpenAI’s internal systems until they reached a machine with internet access. They then reached Hugging Face’s production database and obtained the ExploitGym test solutions, which let them cheat the evaluation.
OpenAI said at the time that the incident showed advanced AI systems can identify and combine unknown attack paths against real-world systems without access to their source code. It then began investigating whether its models had carried out other unauthorised activity during testing. The Australian access surfaced in that review.
MediaNama’s take:
- First, nobody in Australia detected this. The government learned of the access from an email OpenAI sent to a public inbox three months later, and its national cyber agency heard five days after that. Asked whether his agencies had missed it, Albanese said the portal was “not a security website”. Statistics portals hold no secrets and get the least monitoring. They are also what a research agent goes looking for, which is why three more Australian systems holding health and medicines data may be affected.
- Second, the agent did what an intruder does. It read material the public was not meant to see, and Albanese said Services Australia advises it “engaged in writing files as well to the internal server”. Nobody sent it. It was asked how much Australia spends on medicines, met a block, and worked around it.
- Third, OpenAI controlled everything Australia knows. The company found the access during a review it began after its models broke into Hugging Face, waited three months, then emailed. Six days later it published a disclosure framework that puts third-party cases on a track with no deadline and binds the company to nothing. Albanese, asked when OpenAI knew its agent had gone beyond its task, could not say. Australia now has a taskforce, a parliamentary referral and a possible police investigation, and none of them would exist without that email.
What OpenAI’s framework says about delay: The company published a misalignment reporting framework on September 16, six days after it emailed Canberra. Ready for Disclosure and Minor Investigation cover most cases, and OpenAI expects to publish those quickly. A Larger Investigation, which it calls the Slow Track, covers complex cases involving third parties.
“When a third party is affected, our security, legal, and responsible disclosure obligations take precedence over this framework,” OpenAI said. “We’ll aim to publish an initial notice as soon as possible, but may need to delay it for security reasons.” The company said the Hugging Face incident “would have fallen under this track had it been disclosed under this framework”.
OpenAI went further on the state of the field: “We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.”
Australia’s response:
- A taskforce led by the Department of the Prime Minister and Cabinet, with the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. It will examine whether existing processes can respond to AI-related cyber incidents.
- A referral to the Joint Select Committee on Artificial Intelligence.
- Advice on whether any offences occurred, and whether to refer the matter to the Australian Federal Police.
- Findings that will inform Australia’s AI standards legislation.
Acting Prime Minister Richard Marles said the government is examining whether OpenAI could face penalties. It is “working through” the legal situation and “what it means to have gained an unauthorised access, albeit in an unintended way”, he said, according to SBS.
Albanese ruled out any outside involvement. “There is no suggestion of foreign actors here. This is a research project that has got into areas that it shouldn’t have,” he said. He added that the government could find no precedent for the incident.
How the timeline ran:
- June 18: The agent accessed the portal.
- September 10: OpenAI emailed a Services Australia public mailbox.
- September 15: Services Australia reported it to the Australian Cyber Security Centre.
- Week of September 14: Services Australia informed Minister Katy Gallagher.
- The weekend: Albanese and his office learned of it.
- September 23: Albanese made it public.
What Australia has not said: The government has not named the model involved or described how the agent got past the blocks. OpenAI has not said whether its review found activity on government systems in any other country.
Also read: