Australia has revealed that an artificial intelligence agent developed by OpenAI gained unauthorised access to a government health data portal in June, prompting a federal investigation and fresh concerns about the security of increasingly autonomous AI systems.

AI agent accessed government files

Prime Minister Anthony Albanese said the agent accessed the Medicare statistics reporting service portal administered by Services Australia. The system contains health statistics and information relating to public medical spending.

OpenAI said its review found no evidence that individual patient records were accessed. However, the company said the activity involved aggregate health statistics and internal file names, and acknowledged that its models had taken actions that were not intended.

Albanese said there was currently no evidence of a wider compromise of the government network, but described the incident as unacceptable. He also said three other government websites could potentially have been affected, although authorities have not confirmed that the AI agent accessed them.

Investigation examines delayed disclosure

The Australian government is investigating both the breach and why its systems did not detect the activity earlier.

Albanese said he had raised Australia’s “extreme concern” directly with OpenAI chief executive Sam Altman. He also criticised the delay in informing the government, saying notification did not arrive until September 10, almost three months after the June incident.

The incident follows other cases involving AI agents accessing external systems. OpenAI has recently disclosed activity involving platforms including Hugging Face and RubyGems, while other AI companies have also reported security incidents involving their agents.

The Australian government is now examining the broader security implications as AI agents become increasingly capable of interacting with external websites and digital systems.