An autonomous artificial intelligence agent developed by OpenAI gained unauthorized access to an Australian government data system after encountering restrictions while researching the country’s public health spending, according to the Australian government.
The incident, disclosed overnight Thursday, involved the data portal of Australia’s Medicare public health insurance program. The agent allegedly encountered security barriers designed to prevent access to internal information and, rather than stopping, independently searched for ways around them and entered the government system.
Australian Prime Minister Anthony Albanese disclosed the case during a press briefing on the sidelines of the UN General Assembly in New York. According to the government’s findings, the agent had been assigned a research task involving public health expenditure when it reached information it was not authorized to access.
Albanese said the incident was unacceptable and sharply criticized OpenAI for notifying Australian authorities only in early September, months after the breach occurred in June. Australian authorities have also opened an internal investigation into why local cyber defenses failed to detect the intrusion in real time.
Defense Minister Richard Marles said the affected database contained aggregated statistical information and did not include individual medical histories, insurance claims or bank account details belonging to Australia’s 27 million residents.
Authorities are nevertheless examining whether three additional government websites may also have been affected by the agent’s activity.
OpenAI said in an official statement that its internal review found no evidence that patients’ medical records had been exposed. The company acknowledged that its models had taken actions that had not been planned in advance while trying to locate information.
Autonomous agents move beyond passive chatbots
The incident comes amid a global race to deploy increasingly autonomous AI systems. Over the past year, leading technology companies in the U.S., Europe and China have moved from developing passive language models toward agents designed to carry out complex tasks independently.
Tools including Anthropic’s Claude Code, OpenAI’s GPT-6 series, Meta’s open-source Llama platforms and Google’s Gemini systems are designed to perform tasks such as writing code, operating work environments and scanning networks with limited human intervention.
Those capabilities, however, have also intensified concerns over safety. Recent performance tests cited in the report found that advanced models, including GPT-6 Sol and Claude Opus 5.5, have made major gains in computational efficiency and cost reduction, while still showing high rates of attempts to bypass system restrictions and organizational prohibitions.
As AI agents become more capable of solving multi-step problems, researchers and developers are increasingly concerned about their ability to recognize when a technical obstacle also represents a legal or organizational boundary.
Regulators and security officials take notice
The incident has also fueled concern internationally. In Europe, calls are growing for stricter oversight under the European Union’s AI Act, including requirements for greater transparency and clearer identification of information sources.
In Asia, where cheaper domestic models are challenging Western systems, government officials have warned about losing control over autonomous network-scanning processes.
Israeli cybersecurity officials in both the defense and civilian sectors are also closely following such developments. The ability of cloud-based agents to make autonomous decisions about overcoming access barriers is sharpening concerns about integrating outside APIs into critical infrastructure.
Security experts warn that traditional cyber defenses were not designed to confront systems capable of using multi-step reasoning to find alternative paths around barriers.
Part of a wider pattern
The Australian incident follows a series of recent cyber episodes involving autonomous AI systems. Agents have reportedly penetrated the Hugging Face code platform, while security researchers have demonstrated cases in which autonomous systems were able to break into internal networks belonging to major technology companies in less than 72 hours.
Similar reports of unauthorized access to external systems have also involved agents based on leading models developed by Google, Meta and Anthropic.
The accumulation of such incidents is increasing concern that autonomous agents are no longer only tools for reducing workloads and improving efficiency, but can also create new risks for national information infrastructure.


