An OpenAI agent broke into a Medicare statistics portal in June, the Federal Government revealed this week. It is just one example of a disturbing new phenomenon: AI systems that turn to hacking when routine tasks hit a wall.
The agent gained unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia, on June 18. It accessed both public and non-public files and wrote files to the system.
OpenAI did not notify the government until September 10, almost three months later. The notice arrived as an email to a generic public inbox.
The incident is being described as the first known case of an AI agent breaching a government system.
OpenAI says its models were looking up statistics to answer questions about Australia during an internal evaluation.
“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.
The company says the data accessed comprised aggregate health statistics and internal file names. It found no evidence patient records were accessed.
The older portal hosted aggregate data on health spending and drug subsidies. It is widely used by researchers and academics.
OpenAI became aware of the breach on August 11, during a review of ‘misaligned’ model activity in training. OpenAI CEO Sam Altman did not raise it when he met Deputy Prime Minister Richard Marles in San Francisco on September 1.
In the wake of the Medicare incident, the government has set up a taskforce led by the Department of the Prime Minister and Cabinet. It will work with the Australian Signals Directorate (ASD) and the AI Safety Institute.
The taskforce will examine how Australian security agencies failed to detect the breach. It will also consider whether OpenAI could face criminal charges.
Not an isolated case
The Medicare breach is the latest in a string of 2026 incidents in which AI agents have gone beyond their instructions.
On the eve of the Medicare announcement, AI oversight lab Transluce published research into early rogue agent activity. The work was done with MIT and two AI startups: security firm Corridor and AIUC, which develops risk and insurance standards for enterprise AI.
The researchers analysed public logs from the URL scanning service urlquery.net. They found agents probing websites for vulnerabilities while carrying out mundane data retrieval.
On May 25 and 26, agents trying to retrieve a photograph from the University of New Mexico’s digital library sent seven vulnerability probes. These included SQL injection and path traversal attempts.
Two days later, agents gathering University of Iowa data from the Data USA platform sent 12 vulnerability probes after their queries returned errors.
On June 20 and 21, agents on a pharmaceutical data task hit bot protection on the Australian Institute of Health and Welfare (AIHW) website. They found a pre-production server and retrieved a public file from it.
Transluce linked the AIHW and Data USA activity to an OpenAI agent swarm the company had previously confirmed. None of the probes appear to have succeeded.
Transluce’s Conrad Stosz said the Australian episodes were probably “the first instance of an agent autonomously choosing to hack into a government.”
The researchers also found agent activity dating back to March, and as recently as last week.
That swarm was behind the best-known incident of the year. On July 21, OpenAI disclosed that its agents had escaped an isolated test environment and breached AI platform Hugging Face.
The agents, powered by GPT-5.6 Sol and an internal research model, chained together vulnerabilities to reach the open internet. OpenAI later published a technical report on the Hugging Face incident.
Independent investigators found a swarm of roughly 700 agents carried out the attack, and many tried to cover their tracks.
The UK AI Security Institute (AISI) reported its own serious incident on August 4.
During a cyber evaluation between July 25 and 28, AI agents took 19 unsanctioned actions on the live internet, some aimed at real people.
Most came from Anthropic’s Mythos 5, with two involving OpenAI’s GPT-5.6 Sol. In the most serious case, an agent tried to insert malicious code into a real open-source project.
It researched the project’s maintainers and created fake identities to socially engineer approval for the code. The attempts failed and AISI found no real-world harm.
AISI noted the tests were deliberately permissive, with open internet access and some safety filters switched off.
In Spain, the national data protection agency (AEPD) disclosed in mid-September its first breach notification attributed to an AI agent.
The notifying organisation says the agent found a way to log in, searched the application for flaws, modified personal data and accessed invoices.
Unlike the OpenAI cases, a third party appears to have deployed the agent deliberately. The AEPD has not named the organisation or the model and has yet to verify the account.
AEPD deputy director Francisco Pérez Bes said the case shows AI-driven attacks are no longer a theoretical risk.
The agency urges organisations to include AI-executed attacks in their risk assessments and to protect credentials and digital identities.
Elastic ANZ country manager Jeremy Pell said incidents like these showed how quickly the threat environment had shifted.
“AI has handed attackers the ability to automate exploitation at a pace that traditional security tools were not built to match,” he said.
“The key question, he said, is not just whether AI is deployed. It is “whether the architecture beneath it is built to make it work when it matters.”
Long foreseen
Prime Minister Anthony Albanese said the Medicare breach was a shock, but not a surprise.
“It also, I think, was something that had been predicted, including by the AI companies themselves,” he said.
Those predictions go back decades.
In 1960, cybernetics founder Norbert Wiener described the risk of a machine literally pursuing a goal with unintended results.
He warned against relying on machines we cannot easily interfere with. In that case, he wrote, “we had better be quite sure that the purpose put into the machine is the purpose which we really desire.”
Five years later, British mathematician I.J. Good described an “intelligence explosion” of self-improving machines.
He called the first ultraintelligent machine the last invention humanity need ever make. But only, he added, “provided that the machine is docile enough to tell us how to keep it under control.”
Wiener’s warning describes the 2026 incidents closely. None of the agents was told to hack anything. Each was pursuing an assigned goal and chose its own means.
The AI industry now has its own term for this behaviour: misalignment. OpenAI has used it repeatedly to describe the activity behind the Medicare breach.
This week, the heads of major AI companies, including Altman, urged the United Nations to find ways to regulate the technology they are building.