AI Agent Breaches Australian Government Portal

Share f X WA in

CANBERRA: An OpenAI AI agent gained unauthorised access to infrastructure behind an Australian government Medicare statistics portal while conducting research into public medicine spending, prompting the Australian government to launch an urgent investigation.

Australian Prime Minister Anthony Albanese said the incident occurred on June 18 and involved the Medicare Statistics Reporting Service portal, administered by Services Australia. The portal is a public-facing website containing aggregate Medicare and Pharmaceutical Benefits Scheme statistics and is separate from systems handling individual Medicare claims, payments or patient records.

According to the Australian government, the AI agent was conducting internet-based research as part of an internal OpenAI capability evaluation. After encountering restrictions while seeking information, the agent found a way around those controls and gained access to areas it was not authorised to enter.

The agent accessed both public and non-public files, including aggregate health statistics and internal file names. Australian authorities and OpenAI have said there is currently no evidence that individual patient or Medicare records were accessed. The government has also said there is no evidence of a broader compromise of the Services Australia network.

The incident was discovered by OpenAI in August during the company’s review of what it described as misaligned model activity. The company notified Services Australia by email on September 10, nearly three months after the incident occurred. Services Australia subsequently referred the matter to the Australian Signals Directorate’s Cyber Security Centre on September 15.

Albanese said he spoke directly with OpenAI CEO Sam Altman and expressed the Australian government’s concern about both the incident and the delay in notifying authorities.

The prime minister has established a task force to conduct an urgent review of the incident and determine whether Australia’s existing processes are adequate for dealing with cyber incidents involving autonomous AI systems. The review will involve the prime minister’s department, the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.

Australian officials said the AI model also interacted with three other government websites during the broader evaluation: the Australian Institute of Health and Welfare, the Victorian Department of Health, and the NSW Bureau of Crime Statistics and Research. Officials said those interactions involved access to publicly available information and were considered normal, unlike the unauthorised access involving the Medicare statistics portal.

OpenAI said it was conducting an extensive review of unexpected model activity and had identified activity involving several Australian government websites while its models were attempting to answer questions about Australia. The company said its review found no evidence of patient records being accessed.

The incident comes amid wider concerns about the behaviour of increasingly autonomous AI systems. OpenAI recently identified six instances of concerning or unexpected model behaviour as part of its work on monitoring what it calls misalignment, including cases involving attempts to bypass restrictions or evade oversight.

The Australian investigation will also examine whether existing laws, cybersecurity safeguards and information-sharing arrangements are sufficient to address unexpected actions by AI agents that can independently browse the internet and interact with digital systems.

For now, Australian authorities have stressed that while the unauthorised access is being treated seriously, there is no evidence that individual medical records were compromised. The investigation is continuing to establish the full scope of the incident and determine what additional safeguards may be required for autonomous AI systems.