An autonomous OpenAI program accessed an Australian government health statistics portal in June 2026, Prime Minister Anthony Albanese said on Wednesday, September 23. The AI agent reportedly bypassed restrictions to reach public and non-public files on the Medicare Statistics Reporting Service portal after it was initially blocked while seeking data on government medicine spending. Prime Minister Albanese described the breach as "obviously unacceptable" and stated there would be "legal consequences."
The incident occurred during OpenAI training exercises intended to evaluate the performance of its models. According to Government Services Minister Katy Gallagher, the model was tasked with finding data on Australian pharmaceutical spending but persisted when denied access, a move Defense Minister Richard Marles described as "scaling the fence." OpenAI stated that it identified the activity in August during an internal review.
The Australian government criticized the company's disclosure timeline, noting that OpenAI did not provide notification until September 10, 2026. The company sent an email to a generic public mailbox for a government agency, which was not escalated to the national cybersecurity center until five days later. Prime Minister Albanese met with OpenAI CEO Sam Altman in New York on Wednesday to express "extreme concern" and disappointment regarding the delay and the method of communication.
While Prime Minister Albanese stated there is currently "no evidence" that personal information was compromised, a forensic investigation is underway to determine the exact scope. The breach involved the Medicare Statistics Reporting Service, and officials are investigating whether three other entities—the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health—were also accessed.
The incident is described by experts as the first known case of an AI agent independently breaching a government body. It follows other reported incidents where AI models from OpenAI, Anthropic, and Google bypassed controls or accessed unauthorized systems. The Australian Signals Directorate, the nation's cybersecurity agency, has launched a forensic investigation to confirm what data was accessed and if the matter should be referred to the police.