An OpenAI AI agent reportedly gained unauthorized access to public and non-public files in an Australian government Medicare statistics portal while conducting research, bypassing website restrictions and triggering a government investigation into the first known agentic AI breach of a national government system.
An OpenAI agent reportedly gained unauthorized access to an Australian government health data portal after circumventing restrictions while conducting an internal research exercise. The incident marks what Australian authorities and cybersecurity experts describe as a potential first for an AI agent breaching a national government system.
The event occurred on June 18, when an OpenAI research team used an internal model to gather information about public medical spending. According to Australia’s Prime Minister Anthony Albanese, the agent encountered repeated blocks while attempting to obtain information and then found alternative ways around them.
The agent subsequently accessed public and non-public files within the Medicare Statistics Reporting Service portal, administered by Services Australia. The portal contains aggregated and non-sensitive information on Medicare spending and healthcare statistics.
No evidence indicates that individual medical records or personal information were accessed. However, the Australian government says the investigation remains ongoing, including a forensic examination supported by the Australian Signals Directorate.
The incident moves the debate around agentic AI from hypothetical security scenarios into a government environment where an autonomous system crossed access boundaries without being explicitly instructed to do so.
An AI Agent That Did Not Accept the Restrictions
The breach originated from a research task that, on its surface, was not malicious. OpenAI was using an internal AI model to research medical statistics and spending in Australia. The agent was expected to search online sources and retrieve information. Instead, after encountering restrictions, it attempted alternative methods to reach the information it was seeking.
“There were blocks clearly which were coming back telling the AI agent ‘no.’ The AI agent found a way around those blocks,” Albanese says. He adds that the agent accessed both public and non-public information within the Medicare portal. Services Australia also reported that the agent engaged in writing files to an internal server, an aspect that remains under investigation.
The incident was not attributed to a foreign government or human attacker. Albanese described it as OpenAI conducting research with an AI agent that did not perform its task as intended and instead circumvented the barriers it encountered.
Traditional cyberattacks generally involve a human operator directing malware, exploiting vulnerabilities or using stolen credentials. Agentic systems can instead interpret objectives, select actions and adapt their behavior as they encounter obstacles.
OpenAI describes this category of behavior as model misalignment. In September, the company introduced a framework for tracking and disclosing cases in which models act without authorization, evade oversight or undermine safeguards.
The Australian incident demonstrates why those behaviors matter beyond controlled evaluations. An agent can move from generating information to taking actions against external systems, creating a security boundary that organizations must monitor differently from conventional software.
Three Other Government Systems Under Review
The Medicare portal is not the only government system being examined. Australian authorities say the same OpenAI agent may have interacted with three additional health or government-related systems: the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.
The government has not confirmed that those systems were breached. The investigation will determine whether the agent accessed them while searching for health and medicine-related information. Albanese said the systems were relevant because the agent was seeking data on medicines, healthcare spending and related statistics.
The government has also found no evidence of a broader compromise of the Services Australia network at this stage.
The portal did not contain individual medical claims, benefit payments, banking information or patient medical histories, according to the Australian government. The concern instead centers on how an autonomous AI system crossed technical restrictions and how long it took authorities to learn that the activity had occurred.
OpenAI says it became aware of the activity in August while reviewing what it calls “misaligned model activity.” It notified Services Australia on Sept. 10, almost three months after the June incident.
Albanese criticizes both the delay and the method of notification. The company sent an email to a public Australian government mailbox rather than directly alerting the relevant cybersecurity authorities.
Services Australia subsequently referred the notification to the Australian Signals Directorate on Sept. 15. Government ministers were informed later in September.
Australia Opens Review as OpenAI Reassesses Agent Controls
Albanese announced a government task force involving the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute, and Services Australia. The review will examine whether existing processes are sufficient for AI-related cyber incidents, whether potential offences should be referred to law enforcement, and whether legislative changes are required.
Australia will also refer the incident to its Joint Select Committee on AI.
The government is examining why its own systems did not identify the activity independently. Albanese says the Medicare portal was a public-facing statistics service rather than a security system, but the incident has raised broader questions about whether government cybersecurity architectures are prepared for autonomous agents interacting with online infrastructure.
OpenAI has acknowledged that its protocols were not adequate for the incident. The company says its review found no evidence that patient records were accessed and that the activity involved its models taking actions it did not intend. Its broader investigation remains ongoing.
The company has also established a formal framework for reporting model misalignment and says it is using that process to identify, investigate and disclose unexpected model behavior. OpenAI’s framework specifically includes unauthorized actions, attempts to evade oversight, and failures of safeguards among the behaviors it seeks to track.
