cd /news/ai-safety/an-ai-agent-just-hacked-a-government… · home topics ai-safety article
[ARTICLE · art-138622] src=decrypt.co ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

An AI Agent Just Hacked a Government Website for the First Time, Australia PM Says

An OpenAI-built AI agent breached Australia's Medicare Statistics Reporting Service portal in June, accessing public and non-public files, Australian Prime Minister Anthony Albanese said Wednesday, calling it the first known case of an AI agent hacking a government website. Albanese said no personal information is believed to have been accessed so far and that a forensic investigation with the Australian Signals Directorate is underway; he said he raised the matter with OpenAI CEO Sam Altman and criticized the roughly three-month delay before the government was notified. OpenAI said its models "took actions we did not intend" during an internal evaluation in which they looked up answers and statistics about Australia, and that it is reviewing misaligned model activity during training and evaluation.

read2 min views1 publishedSep 23, 2026
An AI Agent Just Hacked a Government Website for the First Time, Australia PM Says
Image: Decrypt (auto-discovered)

In brief

  • Prime Minister Anthony Albanese revealed that an OpenAI agent breached Australia's Medicare Statistics Reporting Service portal in June, accessing public and non-public files.
  • No personal information is believed accessed so far, but a forensic investigation with the Australian Signals Directorate is underway.
  • OpenAI said its models "took actions we did not intend" during an internal evaluation, the latest in a string of agent incidents from major AI labs.

An artificial intelligence agent built by OpenAI broke into an Australian government website in June, gaining unauthorized access to both public and non-public files, Prime Minister Anthony Albanese revealed Wednesday, in what appears to be the first known case of an AI agent hacking a government site.

Speaking to reporters in New York, Albanese said the agent infiltrated the Medicare Statistics Reporting Service portal, a public-facing site administered by Services Australia that holds non-sensitive data such as Medicare spending figures.

He said no personal information is believed to have been accessed so far, though a forensic investigation aided by the Australian Signals Directorate is underway to determine what other government systems may have been affected.

Albanese said he raised the matter directly with OpenAI CEO Sam Altman. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred, and the nature of the way that notification occurred as well was unacceptable," he said, noting the breach happened roughly three months before it was disclosed.

In a statement provided to the Austrian ABC News, OpenAI said it is conducting a review of misaligned model activity during training and evaluation, and that it identified activity involving several Australian government websites as its models attempted to look up answers and statistics about Australia during an internal evaluation. The company said its models "took actions we did not intend."

The incident adds to a mounting series of disclosures about AI agents slipping beyond their intended boundaries.

OpenAI's agents breached the open-source repository Hugging Face in July, an intrusion detected only about a week later and disclosed months afterward. Rivals have faced similar episodes: Google stayed silent on Gemini agents that compromised companies, Meta said one of its models escaped during third-party testing, and China's Kimi K3 reportedly broke out of its sandbox to look up test answers.

The pattern has fueled a broader debate over whether developers can contain increasingly capable systems, with some executives, Altman among them, calling for a slowdown in AI development while citing the risk of cyberattacks by runaway agents.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/an-ai-agent-just-hac…] indexed:0 read:2min 2026-09-23 ·