Skip to content
AI agent hacks government website for first time: why this breach matters

AI agent hacks government website for first time: why this breach matters

Nature • September 24, 2026

The Australian Prime Minister Anthony Albanese revealed on 23 September that an artificial-intelligence agent created by technology giant OpenAI hacked into a government health-care website in June, where it accessed private data.

Researchers say this is the first instance of a frontier AI model breaching another country’s government systems. Although no personal health data are thought to have been accessed, the breach is the latest in a series of such incidents perpetrated by agents this year .

OpenAI says the hack occurred during agent training and that it is in the process of notifying third parties of potential impacts on their systems.

News of the security breach comes as global leaders, including Albanese, meet in New York City for the United Nations General Assembly. China’s President Xi Jinping also met with US President Donald Trump on Wednesday for a three-day summit, at which the leaders are expected to AI safety. But analysts say it is unlikely that any deals will be struck.

The latest attack is not surprising and more reports of agents doing things that they shouldn’t are likely to surface, says Jonathan Kummerfeld, who studies AI and human–computer interaction at the University of Sydney in Australia. AI companies run many experiments at the same time and “they probably aren’t seeing everything these models are doing”, he adds.

What did the OpenAI agent do?

In a press conference in New York City, Albanese told the media that an experimental OpenAI agent with access to the Internet was carrying out research on Australian health and medical spending when the agent reportedly gained unauthorized access to the Medicare statistics reporting service. This is a public website that aggregates data on vaccinations, government spending on medical consultations and medicines, as well as organ donor register information.

After being repeatedly blocked from accessing certain information that was not public, the agent was able to work around security measures to access the data, Albanese said.

The breach was not detected by the Australian government. Instead, Albanese said that OpenAI notified them by sending an e-mail to a public government e-mail address, which was “unacceptable”.

Albanese announced an investigation into what happened. “There will obviously be legal consequences,” he added. OpenAI did not respond to questions the incident.

Did the OpenAI agent go rogue?

In a statement, an OpenAI spokesperson said that they identified the breach in August while “conducting an extensive review of misaligned model activity” that occurred during model training. Misalignment is when AI models behave in unexpected ways that don’t align with human laws and values.

During this review, the company identified activity involving several Australian government websites and services. As the AI model attempted to look up answers and available statistics for questions Australia, it “took actions we did not intend”, the spokesperson said. The company is in the process of notifying third parties when a potential breach of their systems occurred, they said.

The incident seems to have happened at around the same time as another cybersecurity incidents involving OpenAI agents. Between May and July, while OpenAI was conducting tests of its agents in a controlled environment, the agents found ways to get around restrictions and gained access to the Internet. Hundreds of agents then targeted an open-source AI platform called Hugging Face, gaining unauthorized access to data sets and accounts.

It is unclear whether the incident involving the Australian website was part of a similar test environment, but Raffaele Ciriello, who studies ethical use of emerging technologies at the University of Sydney, says it’s reasonable to assume that it was.

Ciriello says that the incident isn’t a case of an AI agent going rogue; rather the agent was given instructions to find certain information and in following those instructions it found a way to gain access to non-public information. “The agent is not a legal person,” he says. The responsibility therefore falls on OpenAI and its staff who authorized, configured and supervised the system, he adds.

Enjoying our latest content? Log in or create an account to continue

Access the most recent journalism from Nature's award-winning team

Explore the latest features & opinion covering groundbreaking research

doi:

Reprints and permissions

Will AI really kill us all? The science behind the hype News Explainer 22 SEP 26

Will AI really kill us all? The science behind the hype

News Explainer 22 SEP 26

China punishes prominent academics exposed by research sleuth Career News 21 SEP 26

China punishes prominent academics exposed by research sleuth

Career News 21 SEP 26

Europe pushes for space independence amid geopolitical rifts News 18 SEP 26

Europe pushes for space independence amid geopolitical rifts

AI system helps lab devices ‘talk’ with each other — streamlining research News 24 SEP 26

AI system helps lab devices ‘talk’ with each other — streamlining research

AlphaFold 'goes viral': database adds protein complexes of common viruses News 24 SEP 26

AlphaFold 'goes viral': database adds protein complexes of common viruses

How to stay smart in the age of AI: the science of critical thinking News Feature 23 SEP 26

How to stay smart in the age of AI: the science of critical thinking

News Feature 23 SEP 26

Gravitational tug-of-war inside Earth is changing the length of our days News 23 SEP 26

Gravitational tug-of-war inside Earth is changing the length of our days

AI tool turns any paper into an ‘agent’ that can collaborate and answer complex queries News 16 SEP 26

AI tool turns any paper into an ‘agent’ that can collaborate and answer complex queries

Reimagining research papers as interactive and reliable AI agents Article 16 SEP 26

Reimagining research papers as interactive and reliable AI agents

Postdoc in AI for Biomedicine - Casale Group Join Human Technopole as a Postdoc in AI for Biomedicine, developing AI and multimodal models to uncover the mechanisms underlying human disease. Milan (IT) Human Technopole

Postdoc in AI for Biomedicine - Casale Group

Join Human Technopole as a Postdoc in AI for Biomedicine, developing AI and multimodal models to uncover the mechanisms underlying human disease.

Postdoc in Statistical Genetics - Casale Group Join Human Technopole in Milan as a Postdoc in Statistical Genetics, combining human genetics, AI and multimodal data to uncover disease mechanisms. Milan (IT) Human Technopole

Postdoc in Statistical Genetics - Casale Group

Join Human Technopole in Milan as a Postdoc in Statistical Genetics, combining human genetics, AI and multimodal data to uncover disease mechanisms.

Chemistry Faculty Positions at Westlake University Chemistry at the School of Science is committed to fostering inclusive excellence in a variety of research and teaching activities. Hangzhou, Zhejiang (CN) Westlake University

Chemistry Faculty Positions at Westlake University

Chemistry at the School of Science is committed to fostering inclusive excellence in a variety of research and teaching activities.

Hangzhou, Zhejiang (CN)

Principal Investigators in Neuroscience The Chinese Institute for Brain Research, Beijing (CIBR) ( aims at building a vibrant interdisciplinary research program th... Beijing, China (CN) Chinese Institute for Brain Research, Beijing

Principal Investigators in Neuroscience

The Chinese Institute for Brain Research, Beijing (CIBR) ( aims at building a vibrant interdisciplinary research program th...

Chinese Institute for Brain Research, Beijing

Senior Publisher, Computer Science Journals Job title: Senior Publisher Locations: New York or London — hybrid working model Closing date: October 13, 2026 Springer Nature Springer ... New York City, New York (US) Springer Nature Ltd

Senior Publisher, Computer Science Journals

Job title: Senior Publisher Locations: New York or London — hybrid working model Closing date: October 13, 2026 Springer Nature Springer ...

New York City, New York (US)

Extracted Entities

Attack Types (1)

Countries (2)

Industries (1)

Tools (1)