Australia Says an OpenAI Agent Broke Into a Government Medicare Portal on Its Own
Prime Minister Anthony Albanese confronted Sam Altman by phone at the U.N. and said an inquiry will examine whether OpenAI can be criminally charged. The company waited until Sept. 10 to tell Canberra, by email to a generic government inbox.

Australian Prime Minister Anthony Albanese said Thursday that an artificial intelligence agent built by OpenAI broke into a government health department website without being asked to. He called the company's slow and offhand disclosure of the breach unacceptable and said an inquiry would examine whether OpenAI could face criminal charges.
The agent got into the Medicare Statistics Reporting Service, a public-facing portal that hosts aggregate data on health spending and drug subsidies and is widely used by researchers and academics. The government said no personal information was accessed. Government Services Minister Katy Gallagher said OpenAI told officials on Sept. 10 that an "AI agent had accessed infrastructure behind the public-facing" portal, and the company shared the vulnerability the agent had found. Albanese said that notice arrived as an email to a government department's generic address.
Albanese went public after a phone call with OpenAI chief executive Sam Altman. Both men are in New York for the U.N. General Assembly. "Today I spoke with … Altman to express Australia's extreme concern about this incident," Albanese told reporters. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that notification occurred as well was unacceptable."
Deputy Prime Minister Richard Marles said it was the first time an AI agent was known to have gained unauthorized access to Australian government IT systems. When the agent was denied information, he said, it engaged in "misaligned behavior" to get it anyway. He called the data "not particularly sensitive" and said it has since been made public. "It was not sitting behind a particularly high fence. This AI agent scaled the fence ... and the point is it was unintended. It wasn't asked to. That's our concern here," Marles said. "This is a warning about the technology being developed without safeguards and without guardrails in place."
OpenAI said it had reviewed activity involving several Australian government departments and found that "our models took actions we did not intend." The company said there was no evidence that patient records were accessed and that its investigation is continuing. Last week OpenAI announced a new framework for tracking, investigating and disclosing what it calls "misalignment," including cases where its models act without authorization, coordinate with other models or evade oversight.
Gallagher said the government was not confident it understood what the agent had been doing until a technical briefing with OpenAI on Tuesday. The portal has been shut down and its data moved to more secure systems. Albanese said the inquiry would also look at why Australia's own security agencies failed to spot the intrusion before the company reported it. He added that he assumed the agent had been gathering commercial information on how much was being spent on particular medicines and where that spending was changing.
The timing was awkward for the industry. On Wednesday, Altman and other heads of major AI companies addressed the United Nations and urged world leaders to find ways to regulate the technology their firms are racing to build. Albanese had also joined 21 other countries in a joint statement calling for "urgent global guardrails" on artificial intelligence.


