On 23 September, Australian Prime Minister Anthony Albanese confirmed that an AI agent built by OpenAI breached Australia’s Medicare government site back in June, in what officials describe as one of the first known cases of where an AI access control was gained to a government system, outside the US.
On June 18, the OpenAI agent gained unauthorized access to the Medicare Statistics Reporting Service portal, a public website operated by Services Australia.
No personal Medicare records were accessed, according to the Australian government.
AI Agents Push Beyond Permission
The portal hosts aggregate data on health spending and pharmaceutical drug subsidies and is used primarily by researchers and academics. OpenAI’s agent accessed non-public non aggregate statistics and internal file while attempting to answer questions about Australia’s health spending during an internal OpenAI model evaluation.
“Our models took actions we did not intend,” said OpenAI, claiming the model was part of an internal evaluation, placing AI hacked behavior under review.
Albanese said the agent reached information behind the portal after normal pathways failed. The incident shows how artificial intelligence hacking can emerge without a person ordering a system to break in.
Australia’s Deputy Prime Minister and Defense Minister, Richard Marles, described the behavior as “misaligned,” explaining that when the AI agent was denied information through normal channels, it circumvented access restrictions instead of stopping.
In similar cases to the Australian Medicare breach, agentic AI access is now yet another concern for governments where autonomous systems have learned to treat restrictions as obstacles.
“It was not sitting behind a particularly high fence. This AI agent scaled the fence … and the point is it was unintended. It wasn’t asked to. That’s our concern here,” said Marles, characterizing the AI agent access control data as “not particularly sensitive.”
When Was the Breach Disclosed?
It wasn’t until September 10 that OpenAI notified the Australia government of the agentic AI expanded access – almost three months after the incident took place. The notification was sent as an email to a general public mailbox at Services Australia that is checked only once a day, according to Prime Minister Albanese.
OpenAI said it discovered the AI access control incident during an “extensive review” of its AI models, and according to the AI lab, its models “took actions we did not intent” while attempting to research Australia government statistics.
Albanese criticized the delay and said he had a “very frank discussion” with OpenAI CEO, Sam Altman, over how long the company took to report the incident.
For developers, AI access control cannot rely only on blocking known commands. Agents can retry requests, follow links, or use different tools until they find another route.
Governments Confront Autonomous Access Risks
A forensic investigation led by the Australian Signals Directorate is examining whether other systems were affected. The review shows why access control for AI is becoming a cybersecurity requirement.
The government says there is no evidence of a wider Services Australia compromise. Still, concern is growing around unauthorized AI operating against systems designed mainly to stop human attackers.
Researchers warn that artificial intelligence hacking may become harder to manage as agents gain independence. Unlike chatbots, agents can follow links, call tools, retry steps, and make decisions.
Dr. Rob Nicholls, Senior Research Associate of AI regulation and policy at the University of Sydney, said agents can prioritize tasks over rules.
“The most important thing for that agent is to achieve what that task has been set,” said Nicholls, showing why AI access needs firm limits.
The Australian breach follows earlier reports of OpenAI models behaving unexpectedly during security testing, adding to concern around OpenAI hacks and whether developers can detect risky actions.
That concern grows as companies give systems AI expanded access to browsers, APIs, files and business software. Each connection adds usefulness but can create another route an agent may misuse.
For governments and technology companies, AI access control means limiting what agents can see and use, while recording enough activity to explain a breach. The investigation may determine whether laws were broken, but AI access control must be designed for software that can independently choose its next action.
As autonomous systems spread, cases where AI hacked protected infrastructure may not resemble traditional cyberattacks. Security teams need safeguards that stop persistent agents from turning legitimate tasks into unintended entry.
The incident proves why AI access control must evolve with agent capabilities instead of remaining fixed around human logins and traditional permission systems.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.