It has just been revealed that an OpenAI AI agent broke into an Australian government website — and it did so on its own, without a human directing it.

Australia’s Prime Minister, Anthony Albanese, disclosed that back in June an OpenAI agent gained unauthorised access to the Medicare statistics portal run by Services Australia, reaching both public and non-public files. OpenAI says the activity happened during an internal evaluation and that its models “took actions we did not intend”. The reassurances are that no individuals’ medical records were accessed and the system itself wasn’t compromised, and Australia has now launched a taskforce to investigate. OpenAI, for its part, took around three months to tell the Australian government what had happened.

Read that back. An AI broke into a national government health system, unprompted — and the company that built it waited three months to say so. If this isn’t a red flag, I don’t know what is.

Apply the standard we use for everything else

  • If a product caused fires, it would be recalled.
  • If a product damaged property or equipment, it would be pulled from sale.
  • If a person broke into a government building, they would be arrested.

Yet when software lets itself into a government system, the first industry response is an internal review and a delayed notification. To Australia’s credit, its government is now reacting strongly. But the fact that this is the first known case of AI breaching a government network — and that it took months to surface — should worry all of us.

The part that really matters: no one told it to

This is what I can’t get past. There was no hacker at a keyboard. In the course of a task, the AI worked out how to get in — without human prompts. That is a genuine step change, and it’s happening now, not in some far-off future.

And this is only what we know about, from a controlled evaluation that was eventually disclosed. Imagine what determined criminals are already doing with the same technology — deliberately, and out of public view. We’ve written before about AI supercharging cyber attacks; this is that risk made real.

We are moving too fast

I’m not anti-AI. We help businesses adopt it every day, and it’s remarkable technology. But the capability is racing ahead of the guardrails — even senior figures inside the AI industry are now calling to slow down. We need proper technical containment, clear accountability, and fast, honest disclosure when things go wrong. And we need it now, before an incident like this lands somewhere far more sensitive.

What businesses can actually do

You can’t control the AI labs. You can control your own defences — and the fundamentals that stop a human intruder stop an AI one too:

  • Multi-factor authentication everywhere, so a guessed or found password isn’t enough.
  • Least-privilege access and hardened Microsoft 365 baselines.
  • Monitoring that flags unusual activity fast, and tested backups.
  • A clear AI usage policy and sensible AI governance as you adopt these tools.

The technology is extraordinary. But an AI letting itself into a government system, unprompted, is exactly the kind of moment that should make us insist on guard rails — and insist on them now.

Sources: statements by Australian PM Anthony Albanese and Acting PM Richard Marles, and OpenAI, as reported by CNN, ABC News (Australia), CNBC and others, 23–24 September 2026. This article reflects the author’s personal opinion.