The incident was reported on September 24 by Reuters, citing Australian Prime Minister Anthony Albanese. According to him, an OpenAI agent gained unauthorized access to the Medicare Statistics Reporting Service on June 18 — a government portal for medical statistics managed by Services Australia. The agent was able to open both public and non-public files. ### AI Began Searching for a Bypass As detailed in the published information, the model was conducting a research task related to Australia’s government spending on medications. When automatic requests for the necessary information were blocked, the agent did not stop. According to Albanese, the system found a way to bypass the established restrictions — the Prime Minister metaphorically described it by saying the agent "did not take 'no' for an answer." As a result, the AI gained access to non-public aggregated medical data and internal files. At the same time, Australian authorities emphasize a fundamentally important detail: there is currently no evidence that the agent accessed personal data or medical records of specific citizens. The investigation is ongoing. ### Government Learned Almost Three Months Later No less questions arose about how OpenAI informed the authorities about the incident. The incident itself occurred on June 18, but Services Australia received notification from the company only on September 10. Moreover, the message about a potentially serious cyber incident was sent to a regular public email address of the agency. Only on September 15 did Services Australia notify the Australian Signals Directorate. Albanese stated that he personally spoke with OpenAI CEO Sam Altman and expressed extreme concern about what happened. The Prime Minister also called both the delay in notification and the manner in which the company conveyed information to Australian authorities unacceptable. Now, with the involvement of specialists from the Australian Signals Directorate, a technical investigation is underway. Authorities want to determine what specific data was accessible to the agent and whether it affected other government systems. ### AI Agents Discussed How to Bypass Protection However, the most unusual part of the story emerged after an investigation by ABC Australia. Journalists discovered public logs indicating that several experimental OpenAI agents were trying to find ways to obtain information from Australian government resources. The agents exchanged information about possible methods to bypass restrictions. Among the options were proxies, web page screenshot services, and attempts to guess file names to gain direct access to them. This activity occurred around the same time that OpenAI models gained access to non-public government information. Moreover, the records mention the Australian Institute of Health and Welfare (AIHW) — one of the resources that, according to Australian authorities, the OpenAI model visited. But here a significant caveat is necessary: neither OpenAI nor the Australian government has yet confirmed that the conversations discovered by ABC among the AI agents are directly related to the hacking of the Medicare portal. ### A Special Group Has Been Created After the incident, Albanese announced the creation of a special working group that is to urgently review existing procedures for responding specifically to cyber incidents involving artificial intelligence. It will include the national cybersecurity coordinator, the Australian Signals Directorate, the Australian Institute for AI Safety, the government office on AI, and Services Australia. Authorities also intend to determine whether current legislation is sufficient for such situations and what obligations AI developers should have when incidents are discovered in government information systems. ### Why This Case Attracted So Much Attention Reuters notes that this incident may be the first known case where an AI agent independently hacked a government internet resource. Until now, a significant portion of concerns surrounding autonomous AI agents has related to a potential scenario: the system receives a task, encounters a technical obstacle, and begins to independently seek ways to overcome it. The Australian case shows that such a situation may already arise when working with real government resources. At the same time, the scale of the specific incident, judging by the data currently known, turned out to be limited: personal information of Medicare users, according to preliminary investigation results, was not stolen.