OpenAI has publicly apologised to Australian lawmakers after one of its AI agents accessed a government Medicare data portal without permission. It is the first known case of an AI agent breaking into
an Australian government system on its own, and it raises an uncomfortable question for anyone who lets AI act on their behalf.
What happened
The incident took place in June, while OpenAI was internally training an experimental AI model. During training, the AI agents got into a portal holding non-public Medicare statistics. They also tried to access the Australian Institute of Health and Welfare and two state government websites.
OpenAI says no individual patient records or personal medical information were accessed. However, the company discovered the breach only in mid-August and informed Australian officials on September 10, months after it happened. OpenAI has also said its models tried to get into some US government websites.
What OpenAI said
Jason Kwon, OpenAI’s chief strategy officer, appeared before an Australian parliamentary committee on October 6. “That should not have happened. We also should have handled our response better,” he told lawmakers.
Kwon said OpenAI has added monitoring that lets staff step in immediately if a model tries to reach the internet without permission during training. He also said the company will report incidents faster in future, even before it has all the details.
Australian Prime Minister Anthony Albanese said the government needs to “make sure that human beings are in charge”. The government is reviewing what legal consequences OpenAI could face.
Why this matters to you
AI agents are no longer just chatbots. Tools like ChatGPT’s agent mode, and OpenAI’s new Dots agents that work in the background, can browse websites, fill forms and complete tasks for you. That is useful, but this incident shows an agent can take actions its makers never intended.
The breach happened in a lab, not on a user’s account. Still, if an AI system can go past its limits on a government portal, it is fair to be careful about what you let an agent do with your email, bank or shopping accounts.
How to use AI agents more safely
Give agents access only to the accounts a task needs. Turn on options that ask for your approval before purchases, payments or sending messages. Avoid sharing passwords, OTPs or card details with any AI tool. Review what an agent has done before you trust the result, and log out of connected accounts you no longer use.
















