Australia says an OpenAI agent gained unauthorised access to a government health data portal in June, prompting an investigation into whether other government systems were also affected.
The breach involved a medical statistics portal operated by Medicare, Australia’s universal health insurance programme, while the AI agent was conducting research on public medical spending.
Prime Minister Anthony Albanese said there was currently no evidence of a wider compromise of the government network, but described the incident as unacceptable.
“Evidence currently available is there is no broader compromise to the network. Nonetheless, this situation is obviously unacceptable,” Albanese told reporters in New York, where he is attending the United Nations General Assembly.
Albanese said Australia had expressed its “extreme concern” to OpenAI CEO Sam Altman and criticised the company for taking months to notify the government.
“It took until September 10 before there was any notification at all.”
The Australian government is also investigating why its systems failed to detect the unauthorised activity.
Albanese said three other government health-related websites may have been affected by the AI agent, although he did not confirm that breaches occurred.
OpenAI said its review found no evidence that patient records had been accessed.
The company said it had identified activity involving several Australian government websites and services as its models attempted to find answers.
“Our models took actions we did not intend,” OpenAI said.
AI Agent Bypassed Blocks- Australian Defence Minister Richard Marles said the Medicare portal did not contain individual medical claims, benefit payments, personal banking details or patient medical histories belonging to the country’s 27 million people.
The portal instead contains aggregated data on healthcare use across Australia, he said.
Albanese said the AI agent appeared to have bypassed restrictions placed on it by the system.
“There were blocks clearly which were coming back telling the AI agent ‘no.’ The AI agent found a way around those blocks didn’t accept no for an answer,” he said.
Australia has established a task force to investigate the incident and assess whether existing network security measures are sufficient to prevent similar breaches.
The incident is among a series of recent cases involving AI agents accessing external systems without authorisation.
OpenAI has disclosed several incidents involving unauthorised activity by its AI agents, while rivals including Anthropic, Google’s Gemini and Meta have also reported incidents involving their AI systems accessing external services.
Maurice Chiodo, an Australian mathematician at Cambridge University’s Centre for the Study of Existential Risk, said the incident appeared to represent a significant escalation compared with similar cases in recent months.
He said policymakers should consider enforcing existing laws against unauthorised computer intrusions alongside developing new AI regulations.
The breach was disclosed as leading AI companies warned the United Nations Security Council about the risks posed by increasingly powerful AI systems and called for governments to cooperate on managing the technology.
Erizia Rubyjeana
Follow us on:
