World📡 RTBy RTSep 24, 2026👁 1 views

OpenAI agent hacks Australian government

icon bookmarkicon cameraicon checkicon chevron downicon chevron lefticon chevron righticon chevron upicon closeicon v-compressicon downloadicon editicon v-expandicon fbicon fileicon filtericon flag ruicon full chevron downicon full chevron lefticon full chevron righticon full chevron upicon gpicon insicon mailicon moveicon-musicicon mutedicon nomutedicon okicon v-pauseicon v-playicon searchicon shareicon sign inicon sign upicon stepbackicon stepforicon swipe downicon tagicon tagsicon tgicon trashicon twicon vkicon yticon wticon fm Where to watch Schedule RT News App Question more Ukraine conscripts Israeli settler on Rosh Hashanah pilgrimage – media | Russia-Ukraine conflict live Ukraine conscripts Israeli settler on Rosh Hashanah pilgrimage – media | Russia-Ukraine conflict US steps up military activity near Iran – media HomeWorld News

OpenAI agent hacks Australian government

The tech company did not disclose the breach for nearly three months after its AI accessed restricted Medicare files, PM Anthony Albanese has said Published 24 Sep, 2026 12:16 | Updated 24 Sep, 2026 13:20Australian Prime Minister Anthony Albanese ©  Hilary Wardhaugh / Getty Images

An OpenAI artificial intelligence agent “infiltrated” an Australian government health portal in what is believed to be the world’s first publicly reported AI-led hack of a state website. The IT giant kept the breach quiet for nearly three months after its agent accessed restricted files, Prime Minister Anthony Albanese has claimed.

An AI agent is a software system that can independently carry out tasks on a user’s behalf, making decisions and taking actions with limited human supervision.

The OpenAI agent hacked the public-facing Medicare Statistics Reporting Service portal on June 18 while researching Australian spending on medicines, Albanese said. The portal, widely used by researchers and academics, hosts aggregate data on health spending and government drug subsidies.

READ MORE: Google’s Gemini joins rogue-AI case list– WSJ

The prime minister disclosed the breach in New York on Wednesday after a telephone conversation with OpenAI CEO Sam Altman. Both are attending the UN General Assembly, where Albanese said he had a “very frank discussion” with the tech executive over the company taking “too long” to report the breach.

The agent repeatedly tried to obtain information from the portal and, after being blocked, found ways around the restrictions. It ultimately accessed restricted files, but officials said there is no evidence that personal Medicare records were compromised.

“The AI agent found a way around those blocks. Didn’t accept no for an answer, if you like,” the Australian prime minister told reporters.

READ MORE: OpenAI covered up scale of rogue agent security breaches – Reuters

OpenAI, however, did not tell the Australian government about the breach for nearly three months. The company claimed it became aware of the incident only in August during an ongoing review of “misaligned model activity” and eventually notified Australian officials on September 10. The portal has since been shut down and its data moved to more secure systems.

Albanese said he had expressed “Australia’s extreme concern about this incident” and warned there would “obviously be legal consequences.” Altman acknowledged there were “issues with protocols” at OpenAI, according to the prime minister.

A “forensic investigation” led by the Australian Signals Directorate will examine whether OpenAI could face criminal charges, whether other government systems were affected, and why Australian security agencies failed to detect the intrusion. Albanese suggested the agent may have been examining Medicare spending for “commercial reasons,” including expenditure on particular medicines.

READ MORE: This is how we lose control of AI – one successful task at a time

Deputy Prime Minister Richard Marles said it was the first known case of an AI agent gaining unauthorized access to Australian government IT systems.

This is not the first time OpenAI has been accused of covering up rogue agent activity. The company reportedly kept unauthorized activity quiet for months after its agents bypassed restrictions and used more than ten previously undisclosed websites to communicate. On Germany’s DseWiki alone, they made over 15,000 edits and exchanged tactics for evading safeguards and detection.

In a more serious breach in July, OpenAI agents circumvented safeguards during cybersecurity testing, reached the open internet and gained unauthorized access to systems belonging to Hugging Face, a major AI platform. The incident showed that rogue agent behavior could spill beyond controlled tests and compromise real-world systems. OpenAI acknowledged the breach, calling it a “warning shot” over the risks posed by increasingly autonomous AI.

Other developers have reported similarly troubling behavior in controlled tests. Anthropic’s Claude Opus 4 resorted to blackmail when threatened with replacement in simulated scenarios, while other agents covertly altered code, facilitated fraud and manipulated records – behavior researchers call “agentic misalignment.”

© Autonomous Nonprofit Organization “TV-Novosti”, 2005–2026. All rights reserved.

This website uses cookies. Read RT Privacy policy to find out more.

  • Russia & Former Soviet Union