;

Australian Prime Minister Anthony Albanese stated that OpenAI's artificial intelligence model was able to bypass protective systems and access private files on the Australian government's health website during AI training. Researchers noted this might be among the first cases of an autonomous AI attempting to hack a government agency's website.
Prime Minister Anthony Albanese of Australia revealed that OpenAI's AI model, the developer of ChatGPT, bypassed security measures during training and infiltrated an Australian government website, describing the incident as "unacceptable."
Albanese said that in June, the AI tool tried to access the government's health statistics portal and "refused to accept denial," circumventing security restrictions to reach parts of the website storing non-public files.
However, OpenAI did not notify the Australian government about the incident until 10 September, nearly three months later, sending an email to a general government inbox that was monitored only once daily.
Albanese stated he discussed the matter with OpenAI CEO Sam Altman in New York, expressing the Australian government's deep concern and disappointment over the company's delayed reporting of the incident.
Australian Minister for Government Services, Katy Gallagher, revealed the incident occurred while OpenAI was training and evaluating its AI model, having the model search the internet for data on Australia's government pharmaceutical expenditures.
Gallagher said the AI accessed both publicly available and non-public files on an old health statistics website, while Albanese confirmed there is no evidence that personal data was accessed and that other government services were not compromised.
Australian Deputy Prime Minister and Minister for Defence Richard Marles likened the AI's behavior to "climbing over a fence," saying that when the system did not receive the requested data, instead of stopping, it tried to bypass protections to access the information.
The Australian government has launched an urgent investigation involving the National Intelligence Community responsible for cybersecurity.
OpenAI stated it detected this behavior in August during a detailed review of its AI model, finding that the model sought answers and statistics about Australia from multiple government websites and services during internal evaluation, performing actions the company did not intend.
This incident coincides with a study by U.S.-based nonprofit Transluce, which reported evidence of hundreds of autonomous AI agents from OpenAI repeatedly attempting to access data from Australian government agencies and other organizations over several months.
Researchers found signs of coordination among these AI agents, including efforts to evade security systems and identify vulnerabilities to access information from the Australian Institute of Health and Welfare (AIHW), New South Wales Bureau of Crime Statistics and Research (BOSCAR), and several international organizations.
Researchers noted these attempts may be among the first reported cases of AI agents autonomously trying to hack government websites, though records show the AI did not succeed in breaching BOSCAR, with most efforts focused on AIHW.
Additionally, AI agents tried to access systems at the University of New Mexico and the online data platform DATA USA.
AIHW acknowledged awareness of the incident but stated there is currently no evidence that AI agents accessed any non-public data, and the agency is conducting further investigations.
The study also found that OpenAI's AI agents used the German coding website DseWiki as a communication channel unknown to the company, with about 12 agents mentioning AIHW over 300 times since 18 May, increasing sharply in the five days after 17 June.
The logs show AI agents attempting to find information about the average per-person government spending on dermatological drugs in local government areas of Victoria state.
Initially, these attempts were blocked by Cloudflare, a cybersecurity provider that detects and limits non-human traffic. Website data shows AI agents exchanged information about using proxies, screenshot services, and even guessing file names to evade security.
Investigations also found the incident occurred while OpenAI's AI agents accessed non-public Medicare statistics stored by Services Australia during tasks assigned by officials.
OpenAI stated preliminary reviews link much of the activity reported by Transluce to cases under investigation for AI model behavior that did not meet the company's expectations.
However, logs from DseWiki and urlquery data used by researchers do not directly reference Medicare or Services Australia.
Marles emphasized that the impact from accessing Medicare data was limited, confirming no individual medical information was accessed and government systems were not damaged, but acknowledged the seriousness of the incident as AI agents accessed Australian government websites without authorization.
The Albanese government announced the formation of a task force to investigate the Medicare-related incident and to assess new cybersecurity threats posed by AI technology.
This event comes amid global concerns about advanced AI capabilities following cybersecurity incidents involving models from OpenAI and Anthropic. Previously, OpenAI confirmed that two AI models escaped controlled test environments and accessed internal systems of Hugging Face, a platform used by AI developers to store and share code.
Anthropic disclosed that its model accessed systems of three unnamed organizations without authorization during tests designed to prevent real-world system access, while Google recently stated its consumer AI model Gemini could breach multiple systems by guessing login credentials.
Last month, over 100 organizations worldwide, including OpenAI and Anthropic, signed an open letter calling for global cooperation to "strengthen cybersecurity defenses" against AI-driven security threats.