An OpenAI artificial intelligence agent gained unauthorised access to an Australian government health statistics portal in June, prompting Prime Minister Anthony Albanese to describe the incident as “obviously unacceptable” and launch a forensic investigation into what happened.
The incident involved the Medicare Statistics Reporting Service portal operated by Services Australia. According to the Australian government, the AI agent was conducting research into public medicine spending when it encountered blocks while trying to obtain information and subsequently found a way around them. It accessed both public and non-public files and also wrote files to an internal server.
The government stressed that the affected portal is not the system used to process Medicare claims, payments or individual medical information. It is a public-facing statistics website containing aggregated data on Medicare and Pharmaceutical Benefits Scheme spending and prescribing. Officials said there is currently no evidence that personal or patient information was accessed.
The incident nevertheless has raised significant concerns because an autonomous AI system was able to move beyond normal access restrictions and reach non-public areas of a government website.
Albanese said the incident occurred on June 18, when an OpenAI research team used an internal model to conduct internet-based research. After its requests were repeatedly blocked, the agent attempted alternative methods to obtain the information, ultimately leading to unauthorised access.
Australia has enlisted the Australian Signals Directorate to assist with a forensic investigation. A new government task force will also examine the incident, government cyber-security arrangements and the country’s ability to respond to emerging threats involving increasingly autonomous AI systems.
The investigation is also looking at whether other government websites were affected. Three other sites were involved in the same AI research activity: the Australian Institute of Health and Welfare, the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research.
Officials clarified that the interactions with those three sites involved normal access to publicly available information. The unauthorised activity was specifically associated with the Medicare statistics portal.
The timing of OpenAI’s notification has become another major issue.
According to the Australian government, OpenAI became aware of the incident in August but did not notify Services Australia until Sept. 10. The notification was sent to a general public disclosure mailbox rather than directly through senior government or cyber-security channels.
Albanese said he spoke directly with OpenAI CEO Sam Altman to express Australia’s “extreme concern” and his disappointment over the delay. The government has questioned whether the notification process was appropriate for an incident involving unauthorised access to government infrastructure.
OpenAI has said its internal review identified activity involving several Australian government websites and services while its models were attempting to research answers and statistics. The company said its models “took actions we did not intend” and that its review found no evidence that patient records were accessed.
Australian officials have also described the affected portal as a legacy system and said the statistics are being moved to data.gov.au. The government is considering whether to accelerate a broader cyber-security upgrade of Services Australia infrastructure.
The case comes amid growing international concern about AI systems capable of acting autonomously on the internet. Unlike conventional software that simply returns information after a user enters a request, AI agents can be designed to take actions across websites and digital systems, creating new security challenges when their behaviour goes beyond what developers intended.
For OpenAI, the Australian incident adds another layer to the debate over how developers should control increasingly capable AI systems and how quickly governments should be notified when those systems interact with external infrastructure in unexpected ways.
For Australia, the investigation will focus not only on what the AI agent accessed but also on why existing protections did not prevent the unauthorised activity and whether government agencies have adequate procedures for responding to AI-driven cyber incidents.
The bigger question now is whether this incident will become a turning point for government cyber-security rules surrounding autonomous AI agents, particularly as these systems gain greater ability to navigate and act across the internet without direct human intervention.