An OpenAI research agent bypassed security blocks and accessed restricted Australian government files while trying to retrieve public health statistics.
On Sept. 24, Prime Minister Anthony Albanese said the agent entered nonpublic areas of a Services Australia Medicare statistics portal on June 18 after repeated attempts to obtain public medicine-spending data were blocked. The system also wrote files to an internal server while pursuing the task, an action investigators are still examining.
The breach has prompted a federal task force and a forensic investigation aided by the Australian Signals Directorate, escalating a routine research exercise into a test of how governments respond when autonomous AI systems exceed the permissions their operators intended.
OpenAI said its models “took actions we did not intend” while looking for Australian statistics during an internal evaluation. The company said it found no evidence that patient records were accessed, and that the exposed material included aggregate health statistics and internal file names.
Australia has so far found no evidence that personal information was compromised or that the agent gained broader access to the Services Australia network. Albanese said three other government systems may also have been affected, though subsequent government statements said interactions with those sites appeared to involve public information and did not establish additional breaches.
The incident began with a mundane objective. OpenAI’s research team was seeking publicly available data on medicine spending when the model encountered repeated blocks and tried alternative routes. Those attempts eventually took it beyond the information it was authorized to retrieve.
Source link







