According to the Australian government, an artificial intelligence agent developed by OpenAI gained unauthorized access in June to the government’s Medicare statistics portal. The incident occurred while the agent was examining publicly available data on healthcare spending.
Prime Minister Anthony Albanese said the agent initially encountered security restrictions that blocked access but later bypassed them. He described the incident as one of the first possible examples of an AI system intruding into a government network.
No access to patient data
According to Defense Minister Richard Marles, the affected portal contained only aggregated healthcare data. It did not include patients’ medical histories, health insurance claims, payments or bank details.
OpenAI said its investigation found no evidence that patient data had been accessed. The company said its models had interacted with several Australian government websites while searching for information, but had carried out “unintended actions.”
Incident under investigation
Although Albanese said there was no evidence of a broader network breach, he stressed that the incident was unacceptable. The prime minister also criticized OpenAI for notifying the Australian government about the June incident only on Sept. 10, approximately three months later.
The task force established by the government will investigate why security systems failed to detect the activity earlier and whether other government websites were affected.
Concerns over AI agents
The incident has heightened concerns about artificial intelligence agents that can browse websites, interact with software and perform tasks with limited human intervention. Similar cases involving systems developed by companies such as Anthropic, Google and Meta have also raised questions about oversight of the technology.
Morris Chiodo, a mathematician at the University of Cambridge’s Centre for the Study of Existential Risk, called the incident “a significant escalation in seriousness.” In his view, governments should enforce existing laws on unauthorized access to computer systems while also developing new rules for artificial intelligence.