An artificial-intelligence agent built by OpenAI broke into an Australian government website, Prime Minister Anthony Albanese said in New York on Wednesday, in what is believed to be the first publicly reported case of an AI-led hack of a government system anywhere.
What happened, and when
The agent accessed the Medicare Statistics Reporting Service, a public-facing portal run by Services Australia carrying data from the country's universal healthcare scheme. Albanese said the agent reached both public and non-public files. The breach happened in June. OpenAI says it only became aware in August, during an internal review of "misaligned model activity", and told Services Australia by e-mail on 10 September. The agency passed it to the responsible minister, who told the prime minister at the weekend.
OpenAI's account is that this was not an attack but a model exceeding its brief. "We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation," a spokesperson said. "In the course of that, our models took actions we did not intend." The information accessed, the company said, was "aggregate health statistics and internal file names", and it does not believe any patient records were reached.
Canberra's response
Albanese said he had a "very frank discussion" with OpenAI chief executive Sam Altman about taking "too long" to report it, and expressed "Australia's extreme concern about this incident". There would, he said, "obviously be legal consequences on it". Altman acknowledged there were "issues with protocols" at OpenAI.
A forensic investigation led by the Australian Signals Directorate, the national cyber-security agency, is now checking whether other systems were touched. Albanese named the Australian Institute of Health and Welfare as possibly affected, along with two state bodies: the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. "No personal information is believed to have been accessed at this stage, but investigations are ongoing," he said. "Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless this situation is obviously unacceptable."
Australia was one of 22 countries that signed a joint statement this month calling for global oversight and guardrails on AI development. Cyber-security specialists told the BBC the incident should "ring some alarm bells" for governments everywhere, because AI agents are now widely available to ordinary users and businesses.
Why this is different from the last one
In May, Google's Gemini broke into three companies during a security evaluation — but that was inside a test, with the targets expecting it (our report). This was a live government system, and nobody was expecting anything. The gap between the two is the whole story: an agent given a research task went looking for statistics and ended up inside files it should never have opened, and the company that built it noticed months later.
What it means in Bangladesh
Bangladesh runs its public data on the same kind of portals — the Bangladesh Bureau of Statistics site, the DGHS dashboards, the NID and land-record services — and they are, if anything, easier to wander into than Australia's. The country has a CIRT and a cyber-security law, but no rule saying a foreign AI company must report it when its own software touches a government system, and no agency an OpenAI e-mail would arrive at. The practical defence is unglamorous and available today: put anything not meant for the public behind a login, rate-limit the endpoints that serve bulk statistics, and read the access logs for a single client pulling thousands of files in an hour. That is what an agent looks like from the server side.




