OpenAI Agent Hacks Australian Government Portal

The Australian Prime Minister, Anthony Albanese, has disclosed that an AI agent, developed by OpenAI, hacked a government portal. This seems to be one of the world’s first examples of an AI-led attack on a government website. It comes as international leaders and AI firms call for faster regulation, with growing concern that the technology is developing more quickly than current safeguards can manage. 

Speaking today, whilst attending the UN General Assembly in New York, Mr Albanese said that the agent infiltrated part of the Australian government’s healthcare scheme Medicare. The hack took place in June, though OpenAI became aware of it in August and informed the Australian government in September. The company said, “our models took actions we did not intend” and that it found no record of patient data being accessed. The Australian government has launched an urgent review. 

Notably, an AI-enabled hack of this kind was anticipated by Caroline Wong, an AI expert, during an appearance on the Guardians of Data podcast in June. Listen to the clip here.  

This case highlights the importance of ensuring that all AI has effective governance controls in place and is properly tested before being deployed. This is particularly important in the case of AI agents. For the past few years, legal, compliance and data protection professionals have largely focused on the risks associated with deploying large language models (LLMs) such as ChatGPT and Claude.  

The key difference between LLMs and agentic AI is autonomy. Traditional AI tools usually operate within a defined task and rely on people to decide what happens next. By contrast, agentic AI can adjust its actions as information changes, tools become available or the task develops. This increases the risks substantially. 

An agentic system may be linked to internal systems, third-party services, customer information, APIs and external tools. Each connection creates potential cyber security exposure. If an agent has excessive permissions or is badly configured, an attacker may be able to influence its actions, redirect it towards an unintended outcome or gain access to sensitive commercial or personal information. 

For a detailed discussion on the risks of AI Agents see our blog post. You can also hear more on building trustworthy and responsible AI systems with AI expert Tahir Latif in this podcast. 

We are repeating our fully booked AI Agents webinar in November. It will equip you with the knowledge needed to understand, assess, and govern AI agents confidently and responsibly.