;

Australia revealed that OpenAI's AI accessed health data from a government agency without authorization in June, but no evidence has been found that patient data was viewed. This marks the first known case of AI hacking a government website.
On Wednesday, 23 September, the Australian government disclosed that an AI agent from OpenAI accessed a government health data portal without permission in June, gaining access to some files including both publicly available and internal data. This incident may be the first public case of an AI agent breaching a government website.
Australian Prime Minister Anthony Albanese said the AI agent accessed the government agency's medical statistics portal, which handles health data and non-sensitive statistics, including information related to public health expenditures.
During a press conference in New York, where he was attending the United Nations General Assembly, Albanese stated that current evidence shows no widespread breach of government networks but acknowledged the incident is unacceptable.
The Australian government is still investigating the incident. Albanese said the government expressed strong concerns to OpenAI CEO Sam Altman and criticized the company for taking a long time to report the incident to authorities.
Albanese noted that the government was only informed on 10 September, despite the incident occurring in June, and the investigation will examine why government systems failed to detect the unauthorized access sooner.
Additionally, Albanese revealed that three other government websites might have been affected by the AI agent's activities, although it has not been confirmed whether the AI actually accessed those sites.
OpenAI stated that investigations so far have found no evidence of patient record access. The accessed data included aggregate health statistics and internal file names.
OpenAI further explained that the company detected activity involving several Australian government websites and services as the AI model tried to find answers, admitting that the model performed some unintended actions.
This incident comes amid global concerns about the security of AI agents—AI systems capable of autonomously performing actions on external networks. Previously, there have been multiple reports of AI agents accessing external systems without authorization.
One notable case involved a breach of Hugging Face, an open-source AI platform, in mid-July, which was detected about a week after it occurred according to timelines released by OpenAI and independent researchers.
Besides OpenAI, other AI companies like Anthropic, Google—which develops Gemini—and Meta have also disclosed incidents where their AI agents accessed external systems without authorization.
These developments have sparked global debate about the risks associated with advancing AI capabilities. Leading US AI company executives, including Sam Altman, have called for a pause in AI development due to cybersecurity risks posed by potentially uncontrollable AI agents.
Click to read related news aboutInternational news