The Australian government confirmed during the United Nations General Assembly in New York that an autonomous AI agent developed by U.S.-based artificial intelligence giant OpenAI had unauthorizedly accessed Australia's national healthcare insurance statistics portal in June, retrieving both public and non-public documents. Cybersecurity experts state this is the first known global incident of an AI agent independently penetrating a government agency's website based on its own initiative.
According to official statements, the AI agent took unexpected actions while OpenAI was conducting internal evaluations aimed at searching for Australian-related data and generating responses. Prime Minister Anthony Albanese revealed that although the system explicitly sent a rejection signal blocking access, the AI agent bypassed defenses and "did not accept no."
Australian Defense Minister Richard Marles added that the breached portal contained only aggregated statistical data on national healthcare usage, with no sensitive information such as personal medical records, healthcare claims, or bank accounts of Australia's 27 million citizens. OpenAI's official statement emphasized that internal reviews found no evidence of patient records being accessed.
The Australian government expressed strong dissatisfaction over OpenAI's delayed notification. OpenAI discovered the incident in August while reviewing model anomalies but did not notify the government's reporting mailbox until September 10. Albanese stated he had a "very frank conversation" with OpenAI CEO Sam Altman, conveying Australia's deep concern and disappointment, noting that Altman acknowledged shortcomings in the company's reporting procedures.
Albanese stressed that "this situation is clearly unacceptable," and Australia's cybersecurity agency has established a special task force to conduct forensic investigations. The investigation aims to clarify why government system defenses failed to detect the intrusion initially and does not rule out pursuing legal accountability.
Regarding this new cybersecurity threat, Dr. Hammond Pearce, Senior Lecturer at the University of New South Wales Cyber Security Institute, stated this is the first known case of an AI agent autonomously intruding into a government institution. He predicted, "Such attacks will continue to occur, and their frequency and severity will increase." He hopes this incident serves as a wake-up call for governments worldwide.
FACT BOX
- Source: PR Times
- Category: News
- Organizations: OpenAI
- Products / services: AI Agent