Dark Mode
More forecasts: Johannesburg 14 days weather
  • Thursday, 24 September 2026

Australian Government Health Portal Hacked by Rogue OpenAI Model

Australian Government Health Portal Hacked by Rogue OpenAI Model

An artificial intelligence agent developed by OpenAI infiltrated an Australian government healthcare portal in June, marking the first recorded instance of an AI system breaching a national government network on its own volition.

 

The breach targeted the Medicare Statistics Reporting Service, a database housing public and non-public files from Australia's universal healthcare system. Prime Minister Anthony Albanese revealed the incident during the United Nations General Assembly in New York, confirming the agent bypassed system controls to read and write files without human instruction.

 

The intrusion occurred in June when the OpenAI model attempted to retrieve statistics for an internal evaluation and bypassed access restrictions. However, OpenAI stated it only discovered the activity during an August audit of "misaligned model activity".

 

On September 10th, OpenAI sent an email detailing the breach to a general, unmonitored inbox belonging to an Australian government agency. The message sat unread for five days before being escalated to the Australian Signals Directorate (ASD) and senior government ministers.

 

In response, Albanese held a direct conversation with OpenAI CEO Sam Altman to express Australia's "extreme concern about this incident" and disappointment over how long it took to notify officials. Albanese noted that Altman acknowledged "issues with protocols" within the company.

 

"It took the company way too long to inform the government what had occurred, and the nature of the way that notification occurred as well was unacceptable."

 

"I think OpenAI knows that they need to have better protocols in place."

 

OpenAI spokesperson Drew Pusateri acknowledged the system went beyond its intended scope during internal testing:

"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend."

 

A forensic investigation led by the Australian Signals Directorate and a newly formed defense taskforce is determining whether additional government systems were compromised.

 

The investigation is reviewing three other public entities that may have been targeted:

  • Australian Institute of Health and Welfare (AIHW)
  • New South Wales Bureau of Crime Statistics and Research
  • Victorian Department of Health

 

Australian Defense Minister Richard Marles stated that the overall operational impact was "relatively minor," assuring the public that "No individuals’ medical data was accessed here. The system itself has not been in any way compromised."

 

Albanese confirmed that Australian authorities will pursue legal options if the investigation determines laws were broken, stating there "will obviously be legal consequences".

 

The revelation coincides with a report from AI research firm Transluce, which documented multiple instances of AI agents attempting unauthorized web exploits as far back as March. In those cases, agents trying to retrieve specific data attempted to bypass anti-bot systems when standard search queries failed, including an attempt to extract data from the University of New Mexico library.

 

In July, OpenAI disclosed that a swarm of its experimental models escaped safety constraints and coordinated to breach systems belonging to tech company Hugging Face.

 

Cybersecurity experts warned that standard government networks remain ill-equipped to handle autonomous digital agents. Walayat Hussain, an associate professor of information technology at Australian Catholic University, said:

"Today’s AI agents are becoming brilliant at getting things done, but they are still poor at knowing where the line is. We cannot rely on AI agents to police themselves, and we cannot ask the companies that build them to mark their own homework."

 

The incident comes immediately after Australia joined 21 other nations at the UN in signing "A Call for Control of Frontier AI Models", an initiative urging international guardrails to maintain human control over rapidly developing artificial intelligence systems.

Comment / Reply From