Cybersecurity

AI agent gains unauthorised access to Australian govt portal

CANBERRA
AI agent gains unauthorised access to Australian govt portal

An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government health statistics portal while conducting research on public medicine spending, prompting a forensic investigation into the incident and whether other government systems were affected.

Australian Prime Minister Anthony Albanese said the incident occurred on June 18, when an OpenAI research team used an internal AI model to conduct internet-based research. The agent encountered repeated blocks while attempting to obtain information and subsequently found alternative ways to access the data, he said.

The agent gained unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia, and accessed both public and non-public files. The government said the portal is a public-facing statistics service containing non-sensitive information, including Medicare spending and other health statistics.

No personal Medicare information is currently believed to have been accessed, although the investigation remains under way. Australian authorities are also examining whether other government systems were affected.

OpenAI said its internal review had identified activity involving several Australian government websites and services as its models attempted to find answers and statistics during an internal evaluation. The company said its models took actions that were not intended and that its review had found no evidence that patient records were accessed.

The Australian government said the incident was detected through notification from OpenAI rather than its own monitoring systems. Albanese said the company notified Services Australia on September 10, nearly three months after the June incident. The notification was sent to a public mailbox, according to the Prime Minister, and Services Australia subsequently referred the matter to Australia's cyber security authorities.

Australia has established a taskforce led by the Department of the Prime Minister and Cabinet, involving the Australian Signals Directorate, the Office of AI, the Australian AI Safety Institute and Services Australia. It will examine the incident, the adequacy of existing processes for responding to AI-related cyber incidents and possible legal or legislative responses.

Three other government systems — the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and Victoria's Department of Health — are also being examined for possible impact. Authorities have not confirmed that these systems were compromised.

The incident comes as governments and technology companies assess the security implications of increasingly autonomous agentic AI systems, which can use internet connections, software tools and external data sources to pursue assigned tasks. Australia's Signals Directorate has previously warned that such systems require controls including limited permissions, monitoring and human oversight because connecting AI models to external systems can expand their security exposure.

The Australian investigation is continuing, with authorities seeking to establish precisely what the AI agent accessed, how it bypassed the portal's controls and whether any other systems were affected.