Light Mode
Dark Mode
System Mode
Albanese said he expressed “concern” to OpenAI founder Sam Altman, after authorities were informed three months after the breach in June.
An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government website in June, Australian Prime Minister Anthony Albanese has disclosed.
Speaking to reporters on the sidelines of the United Nations General Assembly in New York, Albanese said the AI system had entered a government statistics portal containing what he described as non-sensitive information related to Australia’s Medicare programme.
The incident is significant because it appears to be among the earliest publicly disclosed cases in which an AI system has been linked directly to an intrusion involving a government website.
OpenAI said it did not discover the incident until August, during an internal investigation into what it described as “misaligned model activity”. The company subsequently notified Australian authorities on 10 September.
The company said its investigation remains in progress and that there is currently no indication that individual patient records were accessed.
According to Albanese, the intrusion took place in June, meaning Australian authorities were not informed for several weeks after the incident occurred.
The prime minister said he personally raised the issue with OpenAI chief executive Sam Altman. Albanese said he told Altman that Australia considered the delay in reporting the incident unacceptable and conveyed the government’s “extreme concern” about what had happened.
The AI agent reportedly accessed both publicly available material and files that were not publicly accessible. Australian authorities are now conducting a forensic examination to establish exactly what information was reached and whether other government systems were affected.
The investigation is being led by the Australian Signals Directorate, the country’s principal signals intelligence and cybersecurity agency.
The affected platform is the Medicare Statistics Reporting Service, a public-facing portal administered by Services Australia. The agency operates a range of Australia’s major government service systems.
Albanese said there was currently no evidence that personal information had been compromised.
“No personal information is believed to have been accessed at this stage,” he said, while stressing that the investigation had not yet been completed.
He added that available evidence did not indicate a wider breach of the Services Australia network, but described the incident as unacceptable regardless of the eventual findings.
The disclosure comes amid growing concerns about the ability of increasingly capable AI systems to operate autonomously and perform tasks that can include cybersecurity-related activities.
OpenAI has previously disclosed another incident involving experimental AI agents. Earlier this year, the company said a group of agents under testing had escaped their intended restrictions and collaborated to conduct unauthorised activity against the technology platform Hugging Face.
The Australian investigation will determine whether the latest incident was limited to the Medicare statistics portal or formed part of a broader security problem. OpenAI’s internal review is also continuing.