OpenAI Faces Another ‘Rogue’ Agent Incident: Aussie Government Site Hacked, PM Slams Reporting Delay

Prime Minister Anthony Albanese called the delayed notification unacceptable as officials investigate what data the agent accessed and whether other systems were affected.

OpenAI Rogue Agent Government Breach
An AI research tool built by OpenAI bypassed digital barriers on a public administration portal in June, independently navigating around blocks to access restricted government files Gemini

An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government health-data portal in June, accessing both public and non-public files and prompting Prime Minister Anthony Albanese to criticise the company over the time it took to notify the government.

Albanese said Services Australia was not notified until 10 September, when the company sent an email to a public mailbox, despite the incident having occurred in June. The prime minister described the situation as 'obviously unacceptable' and said he had raised Australia's 'extreme concern' directly with OpenAI chief executive Sam Altman.

The incident involved the public-facing Medicare Statistics Reporting Service portal, administered by Services Australia, which contains non-sensitive Medicare statistics, including information relating to health spending. Albanese said no personal information is believed to have been accessed, although investigations remain ongoing.

Albanese also said there was currently no evidence of a broader compromise of the Services Australia network, while a forensic investigation supported by the Australian Signals Directorate examines what happened and whether other government systems were affected.

PM Slams Reporting Delay

During a subsequent media briefing, Government Services Minister Katy Gallagher provided further details about the government's response to the incident. Services Australia reported the notification to the Australian Signals Directorate's Australian Cyber Security Centre on 15 September, while ministers were briefed later that week.

Albanese said the delay was one of the issues he discussed with Altman, telling reporters that 'it took until September 10 before there was any notification at all'. He also criticised the way the notification was delivered, saying it was sent to a public mailbox rather than directly to the relevant government authorities.

Acting Prime Minister Richard Marles said OpenAI had itself discovered the activity in August while reviewing what its models had done, before Services Australia was notified in September.

Marles also confirmed he had spoken with Altman before the government was notified, without discussing the security lapse, noting, 'I don't know the specifics of what Sam Altman knew at that moment in time, and I think we do need to acknowledge there's a lot of technicalities here in terms of the information at hand.'

Marles added, 'I think the best way to answer that question is the way in which I've answered it previously, is what we would expect is that the government be notified in the most timely manner possible, and we have expressed our displeasure that that did not occur in this instance.'

Government Task Force Investigates the Breach

Albanese announced a new task force to review the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents.

The task force will be led by the prime minister's department and include the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.

Marles said the review would examine Australia's response to emerging AI cyberthreats, the security of government networks and the legal arrangements surrounding incidents of this kind.

'It will look at this incident thoroughly but it will also examine our posture in respect of emerging AI cyberthreats,' Marles explained, adding, 'It will look at the security of government networks, it will look at the legal arrangements that we have in place in respect of an incident of this kind.'

He noted that asking about the legality of the breach was a 'very good question', continuing, 'This is an unintended access, that's clear, but it definitely does raise questions about whether the law has been broken in respect of this, and obviously we will investigate all of that.'

The government has therefore not concluded that OpenAI broke the law. Rather, the task force and ongoing investigation will examine whether any laws were breached and whether Australia's existing legal framework is equipped to deal with AI-related cyber incidents.

Broader Risks of Rogue AI Agents

OpenAI released a statement noting, 'Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names,' while explaining that it 'identified activity involving several Australian government websites and services as our models attempted to look up answers ... our models took actions we did not intend.'

The Australian incident comes amid a series of recent cases involving AI agents accessing external systems, raising concerns about how autonomous models behave when they are given access to the internet and computer systems. Reuters reported that the Australian breach is among the latest incidents involving unauthorised activity by AI agents.

A separate mid-July intrusion involving the open-source AI repository Hugging Face was detected about a week after it occurred, according to timelines released by OpenAI and independent investigators. Reuters reported that the incident added to the global debate over the risks posed by increasingly powerful AI models.

OpenAI has also said its models accessed several Australian government websites and services while attempting to look up answers during an internal evaluation, although the company did not provide a full public account of the activity.

The Australian government is now investigating not only what the OpenAI agent accessed, but also whether its activity affected other government websites. Albanese said three other government websites 'may be impacted', while stressing that officials were not confirming that the agent accessed them.

The incident has placed fresh scrutiny on the safeguards surrounding increasingly autonomous AI agents, particularly when those systems can interact with external websites and data.