Back Nature AI agent hacks government website for first time: why this breach matters
The Australian Prime Minister Anthony Albanese revealed on 23 September that an artificial-intelligence agent created by technology giant OpenAI hacked into a government health-care website in June, where it accessed private data.
Researchers say this is the first instance of a frontier AI model breaching another country’s government systems. Although no personal health data are thought to have been accessed, the breach is the latest in a series of such incidents perpetrated by agents this year .
OpenAI says the hack occurred during agent training and that it is in the process of notifying third parties of potential impacts on their systems.
News of the security breach comes as global leaders, including Albanese, meet in New York City for the United Nations General Assembly. China’s President Xi Jinping also met with US President Donald Trump on Wednesday for a three-day summit, at which the leaders are expected to AI safety. But analysts say it is unlikely that any deals will be struck.
The latest attack is not surprising and more reports of agents doing things that they shouldn’t are likely to surface, says Jonathan Kummerfeld, who studies AI and human–computer interaction at the University of Sydney in Australia. AI companies run many experiments at the same time and “they probably aren’t seeing everything these models are doing”, he adds.
What did the OpenAI agent do?
In a press conference in New York City, Albanese told the media that an experimental OpenAI agent with access to the Internet was carrying out research on Australian health and medical spending when the agent reportedly gained unauthorized access to the Medicare statistics reporting service. This is a public website that aggregates data on vaccinations, government spending on medical consultations and medicines, as well as organ donor register information.
After being repeatedly blocked from accessing certain information that was not public, the agent was able to work around security measures to access the data, Albanese said.
The breach was not detected by the Australian government. Instead, Albanese said that OpenAI notified them by sending an e-mail to a public government e-mail address, which was “unacceptable”.
Albanese announced an investigation into what happened. “There will obviously be legal consequences,” he added. OpenAI did not respond to questions the incident.
Did the OpenAI agent go rogue?
In a statement, an OpenAI spokesperson said that they identified the breach in August while “conducting an extensive review of misaligned model activity” that occurred during model training. Misalignment is when AI models behave in unexpected ways that don’t align with human laws and values.
During this review, the company identified activity involving several Australian government websites and services. As the AI model attempted to look up answers and available statistics for questions Australia, it “took actions we did not intend”, the spokesperson said. The company is in the process of notifying third parties when a potential breach of their systems occurred, they said.
The incident seems to have happened at around the same time as another cybersecurity incidents involving OpenAI agents. Between May and July, while OpenAI was conducting tests of its agents in a controlled environment, the agents found ways to get around restrictions and gained access to the Internet. Hundreds of agents then targeted an open-source AI platform called Hugging Face, gaining unauthorized access to data sets and accounts.
It is unclear whether the incident involving the Australian website was part of a similar test environment, but Raffaele Ciriello, who studies ethical use of emerging technologies at the University of Sydney, says it’s reasonable to assume that it was.
Ciriello says that the incident isn’t a case of an AI agent going rogue; rather the agent was given instructions to find certain information and in following those instructions it found a way to gain access to non-public information. “The agent is not a legal person,” he says. The responsibility therefore falls on OpenAI and its staff who authorized, configured and supervised the system, he adds.
Enjoying our latest content? Log in or create an account to continue
Access the most recent journalism from Nature's award-winning team
Explore the latest features & opinion covering groundbreaking research
doi:
Reprints and permissions
Will AI really kill us all? The science behind the hype News Explainer 22 SEP 26
Will AI really kill us all? The science behind the hype
News Explainer 22 SEP 26
China punishes prominent academics exposed by research sleuth Career News 21 SEP 26
China punishes prominent academics exposed by research sleuth
Career News 21 SEP 26
Europe pushes for space independence amid geopolitical rifts News 18 SEP 26
Europe pushes for space independence amid geopolitical rifts
AI system helps lab devices ‘talk’ with each other — streamlining research News 24 SEP 26
AI system helps lab devices ‘talk’ with each other — streamlining research
AlphaFold 'goes viral': database adds protein complexes of common viruses News 24 SEP 26
AlphaFold 'goes viral': database adds protein complexes of common viruses
How to stay smart in the age of AI: the science of critical thinking News Feature 23 SEP 26
How to stay smart in the age of AI: the science of critical thinking
News Feature 23 SEP 26
Gravitational tug-of-war inside Earth is changing the length of our days News 23 SEP 26
Gravitational tug-of-war inside Earth is changing the length of our days
AI tool turns any paper into an ‘agent’ that can collaborate and answer complex queries News 16 SEP 26
AI tool turns any paper into an ‘agent’ that can collaborate and answer complex queries
Reimagining research papers as interactive and reliable AI agents Article 16 SEP 26
Reimagining research papers as interactive and reliable AI agents
Postdoc in AI for Biomedicine - Casale Group Join Human Technopole as a Postdoc in AI for Biomedicine, developing AI and multimodal models to uncover the mechanisms underlying human disease. Milan (IT) Human Technopole
Postdoc in AI for Biomedicine - Casale Group
Join Human Technopole as a Postdoc in AI for Biomedicine, developing AI and multimodal models to uncover the mechanisms underlying human disease.
Postdoc in Statistical Genetics - Casale Group Join Human Technopole in Milan as a Postdoc in Statistical Genetics, combining human genetics, AI and multimodal data to uncover disease mechanisms. Milan (IT) Human Technopole
Postdoc in Statistical Genetics - Casale Group
Join Human Technopole in Milan as a Postdoc in Statistical Genetics, combining human genetics, AI and multimodal data to uncover disease mechanisms.
Chemistry Faculty Positions at Westlake University Chemistry at the School of Science is committed to fostering inclusive excellence in a variety of research and teaching activities. Hangzhou, Zhejiang (CN) Westlake University
Chemistry Faculty Positions at Westlake University
Chemistry at the School of Science is committed to fostering inclusive excellence in a variety of research and teaching activities.
Hangzhou, Zhejiang (CN)
Principal Investigators in Neuroscience The Chinese Institute for Brain Research, Beijing (CIBR) ( aims at building a vibrant interdisciplinary research program th... Beijing, China (CN) Chinese Institute for Brain Research, Beijing
Principal Investigators in Neuroscience
The Chinese Institute for Brain Research, Beijing (CIBR) ( aims at building a vibrant interdisciplinary research program th...
Chinese Institute for Brain Research, Beijing
Senior Publisher, Computer Science Journals Job title: Senior Publisher Locations: New York or London — hybrid working model Closing date: October 13, 2026 Springer Nature Springer ... New York City, New York (US) Springer Nature Ltd
Senior Publisher, Computer Science Journals
Job title: Senior Publisher Locations: New York or London — hybrid working model Closing date: October 13, 2026 Springer Nature Springer ...
New York City, New York (US)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
