In a shocking incident involving rogue AI agents, Australian Prime Minister Anthony Albanese revealed that OpenAI’s AI agents have hacked the country’s government health data portal in June. According to a report from Reuters, this incident is potentially the first reported case of an AI agent breaching a government website.
The report highlights that the incident involved a portal which was operated by a government agency that provides health statistics and information. This includes data related to public healthcare spending. However, Australia officials said the portal does not include sensitive patient information.
Reportedly, Albanese said during a media briefing in New York, “Evidence currently available is there is no broader compromise to the … network. Nonetheless, this situation is obviously unacceptable.”
Australia Says OpenAI Took Months To Report Breach
One of the notable concerns raised by the Australian PM is the duration OpenAI took to inform the government about the breach. The incident took place in June, but Australia was not notified until September 10, 2026, according to Albanese. He said he had raised the issue directly with OpenAI CEO Sam Altman and expressed the country’s concern over the delay.
This delay has now led to a wider investigation. As per the report, the Australian officials are also examining why the government’s own security systems did not detect the activity earlier. ABC reported that the breach occurred on June 18 and that Services Australia was notified nearly after three months.
Moreover, the Australian PM reportedly said three other government websites might be potentially affected by the activities of AI agents. However, the government has not confirmed that the agent successfully accessed those websites. “The question is, when it was trying to harvest data, did it go into these other sites? So we’re not confirming that that occurred,” he said.
The Australian incident comes as AI companies increasingly develop agents that can do more than simply generate text. These systems can use tools, search websites, write code and interact with external digital services.
OpenAI has itself acknowledged that newer models are becoming increasingly capable in cybersecurity-related tasks. In September, the company said its GPT-6 Astra model had reached its “Critical” cybersecurity capability threshold under its preparedness framework.
As AI agents continue to advance, the incident turned out to be the first one involving a breach of government website; however, it is yet to be seen how such incidents could become more common as governments and policymakers across the world take the issue to the forums to slow down the pace of AI development.

