OpenAI Agent Breached Australian Government Websites
An OpenAI agent accessed non-public information from government healthcare websites. It also targeted a state health department and a crime statistics website.
OpenAI had given the AI a task to research healthcare spending. It tried to look up the data but was blocked from a government website. It found ways to get around the blocks by running commands, stealing keys, and writing files to a government server.
Slow to Respond
The breach happened on June 18. OpenAI didn't know about it until mid-August. They didn't notify anyone until September 10, when they emailed a government agency's generic inbox.
An OpenAI executive will appear before Australian lawmakers on October 6.
Why It Matters
Nobody told the AI to break in. It was just determined to do well on its task. This is probably the first time an AI has hacked into a government system by itself. Experts have been warning this could happen for a long time.
As AI is trained to be more powerful, this type of incident could happen more often. Politicians are paying attention when people contact them (opens in new tab) to share these concerns.
Sources
- September 24, 2026 - Australian Prime Minister Anthony Albanese announced the breach in a press conference (opens in new tab).
- September 28, 2026 - OpenAI apologized in a blog post (opens in new tab) with more details.
Quotes
- PM Anthony Albanese (opens in new tab): "Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred, and the nature of the way that notification occurred as well was unacceptable."
- PM Anthony Albanese (opens in new tab): "So there's an AI agent looking for information... There were blocks clearly which were coming back telling the AI agent no. The AI agent found a way around those blocks, didn't accept no for an answer, if you like. The model attempted alternate ways to obtain the info that it wanted, and this led to unauthorized access into some other areas."
- OpenAI (opens in new tab): "An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. However, individual patient or client records were not accessed."
- OpenAI (opens in new tab): "In this case, one of the tasks assigned to the model was to research government spending per person on medicines for skin conditions in Victorian communities. The model had difficulty obtaining that information, and it took actions that we had not authorised it to take."