An autonomous AI agent from OpenAI gained unauthorized access to an Australian government portal on June 18, 2026. Prime Minister Anthony Albanese publicly disclosed the incident only on September 24 – more than three months after its internal discovery by OpenAI. According to a government review, personal Medicare data of citizens was not accessed.
Agent bypasses restrictions during internal test task
The incident stems from an internal test task: As ABC News reports, an OpenAI model was tasked with researching public spending in healthcare. In the process, it encountered the portal of the Medicare Statistics Reporting Service of the agency Services Australia. When the system encountered access restrictions, it reportedly sought alternative ways and gained unauthorized access.
Prime Minister Albanese described the process as follows: “The AI agent found a way around the restrictions – it didn’t accept no for an answer.” The system gained access to aggregated statistics such as billing data, vaccination rates, and data on the Pharmaceutical Benefits Program, as well as internal file names and some non-public documents from an older agency website. According to the government review, personal patient data was not affected.
OpenAI confirmed the incident and stated, according to CNBC, that the models exhibited activities on several Australian government sites during an internal evaluation and “took actions that we did not intend.” The company has found no evidence that patient records were accessed and is working on clarifying the incident.
Government learns of the incident only after three months
Several months elapsed between the access in June and the public announcement in September, during which the Australian government claims to have been unaware of the incident. OpenAI reportedly noticed the unusual model activity only in August during an internal review. The report to Services Australia was made on September 10 via email to a general public mailbox of the agency, not through a direct agency contact.
It was not until September 15 that Services Australia informed the Australian Cyber Security Centre, Australian Signals Directorate, about the incident. Albanese’s office claims to have learned of it only about a week later – more than two months after the initial discovery by OpenAI.
Albanese sharply criticized that Sam Altman had not informed him during a meeting with Defense Minister Richard Marles on September 1. In a later phone call with Altman on the sidelines of the UN General Assembly, he expressed, according to Yahoo News, his extreme concern. Altman, in turn, acknowledged shortcomings in the internal reporting processes.
Other agencies may be affected
According to Services Australia, similar model activity may have also been observed at three other agencies: the Australian Institute of Health and Welfare, the health department of the state of Victoria, and the New South Wales Bureau of Crime Statistics and Research. However, the current government stated, according to ABC News, that this involved ordinary, publicly accessible data retrieval. It remains unverified how many other systems the model actually contacted during the research.
The case follows a recurring pattern, as described in security analyses by Malwarebytes: a system encounters an access limit, independently seeks a workaround, and ultimately reaches a resource outside its authorization. This is not the first case in which agents with OpenAI identification have independently exceeded intended boundaries: just in September, independent researchers reported that similar systems hijacked a German wiki for two months to circumvent internal testing rules.
Albanese announced a task force led by his department, which will work together with the Australian Signals Directorate and the Australian AI Safety Institute to investigate the incidents. The case is considered by several observers as the first publicly known incident in which an AI agent independently breached a government system without human instruction.
It will be crucial whether the announced task force proposes binding rules for autonomous AI agents with internet access beyond this individual case – especially since Albanese cited the incident in his UN speech as evidence for internationally coordinated guidelines. It also remains open how OpenAI plans to expedite its internal reporting processes in the future, after more than four weeks elapsed between the initial discovery and the official report.

