Welcome to Roya News, stay informed with the most important news at your fingertips.

Australia's Prime Minister Anthony Albanese participates in the Coalition for the Rights and Protection of Children in the Age of Artificial Intelligence session on the sidelines of the 81st United Nations General Assembly at United Nations Headquarters in New York on September 22, 2026. (Photo by Ludovic MARIN / AFP)

1
Image 1 from gallery

Australian PM says OpenAI hacked government website

Listen to this story:
0:00

Note: AI technology was used to generate this article’s audio.

Published :  
2 hours ago|
  • Australian PM confirmed an OpenAI AI agent bypassed safeguards in June, accessing files on a government health statistics portal.
  • Albanese admonished OpenAI for waiting until September 10 to inform the government via a single email to a generic inbox.
  • Intelligence agencies launched a rapid review, though no personal health records were compromised.

Australian Prime Minister Anthony Albanese publicly admonished artificial intelligence developer OpenAI on Wednesday, disclosing that a rogue model bypassed safeguards during training and hacked an Australian government health website.

Speaking to reporters in New York, Albanese described the breach as "obviously unacceptable" and confirmed he personally raised "Australia's extreme concern" during a direct call with OpenAI CEO Sam Altman.

"Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident," Albanese said. "I also expressed my disappointment that it took the company way too long to inform the government what had occurred."

AI model 'scaled the fence' 

The incident occurred in June while OpenAI ran internal training exercises to evaluate model performance, asking the tool to trawl the internet for data regarding Australian government medical spending.

Government Services Minister Katy Gallagher explained that when the AI tool sought access to the health statistics portal, it "didn't accept no for an answer," systematically sidestepping restrictions to breach a section hosting private files.

"It asked a question, the information was not given and rather than leaving at that point, it scaled the fence," Australian Defence Minister Richard Marles stated.

Despite accessing both public and non-public files, Prime Minister Albanese confirmed there was no evidence that personal information had been compromised or that other government systems were breached.

Australian ministers expressed sharp criticism over OpenAI's handling of the disclosure.

While the breach occurred in June, OpenAI did not identify the rogue activity until an internal review in August.

The San Francisco-based firm subsequently waited until September 10 to alert Australian authorities, sending a message to a general public email address.

"That email address is looked at once a day," Gallagher told reporters. "We have someone who goes and has a look through. It sometimes gets a number of notifications, sometimes many of them are hoaxes."

OpenAI acknowledged the incident in a statement, noting that while attempting to look up available statistics during an evaluation, its models "took actions we did not intend."

In response, Australia launched a rapid review led by its national cyber security intelligence agency.

Rogue AI fears

The breach coincides with growing international concern regarding autonomous AI capabilities, highlighted during a special UN Security Council meeting on AI risks attended by Sam Altman and other industry executives on Wednesday.

The Australian incident follows a series of recent safety failures across the AI sector:

  • Hugging Face Breach: Two OpenAI models escaped a closed testing environment and broke into the internal systems of Hugging Face.
  • Anthropic Testing Failures: Anthropic recently discovered its models gained unauthorized access to three unidentified organizations during testing meant to isolate them from real-world systems.
  • Google Gemini Credential Attacks: Google revealed last week that its consumer AI model, Gemini, hacked multiple systems by guessing login credentials.

In response to rising cyber threats, over 100 organizations globally -including OpenAI and Anthropic- recently signed an open letter calling for international action to strengthen cyber defenses against AI-driven risks.