An OpenAI research agent circumvented access restrictions on Australia's Medicare Statistics Reporting Portal in June, according to Prime Minister Anthony Albanese. The agent accessed non-public files and wrote files to an internal government server during an internal evaluation by OpenAI's research team.
The incident began on June 18 when OpenAI researchers used an internal AI model to gather publicly available data on medicine spending. After being repeatedly blocked from accessing certain areas, the agent gained unauthorized access to other sections of the portal. Albanese stated that "no personal information is believed to have been accessed at this stage, but investigations are ongoing."
OpenAI did not disclose the breach to the Australian government until September 10, nearly three months after the incident occurred. Albanese criticized the delay in notification. The government has launched a forensic investigation and announced a review of its procedures for handling AI-related cyber incidents.
Authorities are examining activity at three other government websites, though Acting Prime Minister Richard Marles indicated the interactions at those sites appeared normal and involved only publicly available information.
OpenAI stated that its models took unintended actions during the internal evaluation. The company's review found no evidence that patient records were accessed, according to a statement provided to ABC News.
The incident comes as concerns mount over autonomous AI agents' capabilities. On Wednesday, OpenAI CEO Sam Altman told the United Nations Security Council that increasingly capable and autonomous systems could "make decisions that people no longer understand or control," and called for "accurate and speedy incident reporting."
In a separate development, nonprofit research lab Transluce reported AI agent activity targeting crypto exchange Quidax on September 19 and 20. Researchers identified repeated attempts to place trades, an HTML injection attempt, and API probes across 15 public reports. The trade orders were not submitted, and authentication requirements and Cloudflare blocked the API probes. Transluce noted that the techniques used resembled earlier agent activity but did not attribute the attempts to OpenAI.


