OpenAI agent hacked Australia government portal: PM Albanese
September 24, 2026
An OpenAI agent infiltrated an Australian government health data portal, Prime Minister Anthony Albanese said Thursday, in what is the first known instance of an artificial intelligence hack of a government system.
Albanese said the breach occurred in June when an autonomous OpenAI program accessed both "public and non-public" files on the statistics reporting portal of Medicare — Australia's publicly funded universal health insurance scheme.
The available evidence did not indicate a broader network compromise, Albanese said, adding, "Nonetheless, this situation is obviously unacceptable."
Albanese said he spoke to OpenAI chief executive Sam Altman to express Australia's "extreme concern" over the incident.
OpenAI, the developer of ChatGPT, said in a statement that it spotted the breach while carrying out an "extensive review" of its AI tools, adding that "our models took actions we did not intend".
Altman had earlier on Wednesday addressed the UN Security Council, apprising the risks AI poses as the world faces the technology's development.
What did Australia's Albanese say about the OpenAI breach?
Albanese told reporters that OpenAI informed Australia about the breach only on September 10, three months after the incident, through an email sent to a public mailbox.
The Australian leader said he expressed his "disappointment" to Altman that it took OpenAI "way too long to inform the government" on what occurred.
Albanese also deemed the nature of the notification "unacceptable."
The prime minister announced that a probe into the security breach would determine whether OpenAI could face criminal charges.
He added that the investigation would also examine how the breach went past Australia's security agencies, which were unaware of it before OpenAI notified them.
How did the breach take place?
The breach occurred as OpenAI ran training exercises to rate the performance of AI models.
Government Services Minister Katy Gallagher said OpenAI asked the model to search the internet for data showing how much Australia's government spent on medicine.
She said the portal had since been closed and the data moved to more secure systems.
Albanese said no personal information is believed to have been accessed during the incident.
"I think OpenAI know that they need to have better protocols in place. And they're one of the businesses that themselves have warned of the risks which are there," Albanese said.
What has OpenAI said?
OpenAI said in its statement that it discovered the rogue activity in an August review.
"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation," it said.
The San Francisco-based company added that it had found no evidence of Australian patient records being accessed.
Australia's Deputy Prime Minister Richard Marles called the breach "fundamentally unacceptable."
"It was not sitting behind a particularly high fence. This AI agent scaled the fence ... and the point is it was unintended. It wasn't asked to. That's our concern here," Marles said.
In July, OpenAI disclosed that its advanced AI model went rogue during a security test and carried out a dayslong hacking spree into the Hugging Face AI technology digital repository.
Days later, rival company Anthropic announced that three separate versions of its AI broke out of cybertesting environments and hacked three firms.
Edited by: Sean Sinico