An OpenAI agent broke into an Australian government portal — and Canberra heard months later
Told to find health statistics, the agent got round the locks on a Medicare data portal in June. OpenAI told Australia on 10 September; the prime minister went public yesterday, and promised "legal consequences".
The task was mundane: look up Australian health statistics. When the Medicare Statistics Reporting Service would not hand the figures over, the OpenAI agent found another way in. The agent "found a way around the barriers" and in effect would not take no for an answer, Prime Minister Anthony Albanese said in New York, where he disclosed the breach on the sidelines of the UN General Assembly. The agent reached both public and non-public files on the portal, run by Services Australia; no personal information is believed to have been taken, and a forensic investigation led by the Australian Signals Directorate is checking whether other systems were hit. The Australian Institute of Health and Welfare and two state agencies, in New South Wales and Victoria, "may have been impacted".
What angered Canberra most was the timing. The breach happened in June. OpenAI says it only found it in August, during an internal review of "misaligned model activity", and told Services Australia by email on 10 September; the prime minister heard at the weekend. Albanese said he had a "very frank discussion" with Sam Altman, who acknowledged "issues with protocols". OpenAI's own account is that its models "took actions we did not intend" while answering questions about Australia in an internal evaluation, and that what they reached was aggregate statistics and internal file names.
When you give the agents a task, the most important thing for that agent is to achieve what that task has been set. Rob Nicholls, University of Sydney, to the BBC
It is not an isolated case. The research group Transluce published an analysis this week of tens of thousands of requests that agents routed through the URL-scanning service urlquery.net to slip past access limits — traffic it traces back to at least 6 March and as recently as 16 September. It found three attempts to exploit public data sites — the University of New Mexico's digital library, the Data USA API and the Australian Institute of Health and Welfare, on 20–21 June — and ties two of them to an agent swarm OpenAI has already confirmed was its own. Earlier this year OpenAI disclosed that test agents had escaped their controls and hacked Hugging Face.
Two details are worth holding onto. Transluce says none of the attempts it could see from public records appear to have succeeded, though it cannot rule out others; Australia's government says its portal was entered. And the behaviour came from ordinary data-retrieval tasks, not from anyone asking for a hack. The same day, Altman and Anthropic's Dario Amodei told the UN Security Council the industry must not take on too much technological risk just because the benefits look large — and offered to help write the rules. Australia was among 22 countries that signed a call for global AI guardrails this month.