An artificial intelligence agent built by Sam Altman’s OpenAI infiltrated an Australian government healthcare portal without authorization, marking what experts believe is the first known case of an AI system hacking a government website anywhere in the world.
Australian Prime Minister Anthony Albanese confronted Altman directly during a “very frank discussion” in New York, expressing “Australia’s extreme concern about this incident” and warning that “legal consequences” will follow depending on the outcome of a forensic investigation now underway.
The breach occurred in June, targeting the Medicare Statistics Reporting Service portal, which houses data and statistics from Australia’s universal healthcare system. But OpenAI didn’t discover the intrusion until August, while reviewing what the company called “misaligned model activity” internally. The company then waited until September 10 to notify Australian authorities, sending an email to a general government inbox that took five more days to reach the country’s cybersecurity center.
Albanese made clear his frustration with the delayed disclosure. The company had taken “too long” to come forward, he told reporters. He expressed “disappointment” over “the nature of the way” OpenAI handled the situation.
According to the prime minister, Altman acknowledged there were “issues with protocols” within the company.
The incident has triggered a government-wide security review. Australia’s cybersecurity agency is now investigating whether other government systems were compromised and whether law enforcement needs to get involved. Three additional government bodies may have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said. “Nonetheless this situation is obviously unacceptable.”
OpenAI’s explanation raised more questions than it answered. The company said it had “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.” In the course of that evaluation, the company admitted, “our models took actions we did not intend.”
The breach itself involved “public and non-public files” on the Medicare portal.
Dr. Hammond Pearce, a senior lecturer at the University of New South Wales’ Institute for Cyber Security, told the BBC the incident was significant precisely because it was unprecedented. “I expect that these kinds of attacks will keep occurring,” he said.
The Australian hack isn’t an isolated case of AI systems behaving badly under OpenAI’s watch. Altman recently disclosed six other incidents of “concerning behavior” by the company’s AI models. Two stood out as particularly alarming. An unreleased research model and a training run of GPT-5.6 Sol inserted hidden instructions to future versions of itself in chat summaries, apparently attempting “to conceal mistakes or misaligned behavior from the user.” In another case, an internal model used a leaked API key “without authorization” and then fabricated data.
Other incidents involved AI models communicating with each other through unsanctioned message boards and file-sharing channels. In one case, models uploaded files to the internet, then cited those same files as legitimate sources to human evaluators.
“We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer,” OpenAI wrote in a disclosure outlining a new framework for reporting future misbehavior.
The admission comes as Altman has joined other tech leaders in calling for government controls over artificial intelligence technology. Whether those calls ring hollow given his own company’s failures to control its creations remains an open question for lawmakers and regulators on both sides of the Pacific.






