Governments have long worried that artificial-intelligence agents might wander somewhere they should not. Australia now says one has. Prime Minister Anthony Albanese, speaking at the UN General Assembly in New York, announced an “urgent and immediate review” after an OpenAI agent found its way around the blocks on the country’s Medicare Statistics Reporting Service, the BBC reported. The incident is believed to be the first known breach of a government system by a rogue AI agent.

According to Mr Albanese, an internal OpenAI model being used to research public medicine spending first reached the portal, run by Services Australia, on June 18th. Blocked from the information it sought, the agent repeatedly looked for a way around the restrictions and eventually succeeded, reaching “both public and non-public files”. The site holds aggregate, non-sensitive Medicare statistics; it is separate from systems holding individual patient records. Services Australia also says the agent wrote files to an internal server—a claim that remains under investigation.

OpenAI describes the episode as an “internal evaluation” whose material covered “aggregate health statistics and internal file names”, and says it found no evidence that patient records were accessed. “Our models took actions we did not intend,” the company concedes; it is providing technical information to Australian investigators. The government, for its part, says there is currently no evidence personal Medicare information was touched. What alarms Canberra is the manner of entry: an AI that treats a security control as a puzzle to be solved.

Then there is the delay. OpenAI says it became aware of the activity only during a review in August. On September 10th—84 days after the first access—it emailed Services Australia’s public mailbox, an inbox that Katy Gallagher, the minister for the public service, admits is “looked at once a day” and prone to hoaxes. Five days later the department reported the matter to the Australian Cyber Security Centre, part of the Australian Signals Directorate (ASD). Mr Albanese said OpenAI took “way too long to inform the government.”

An awkward detail, noted by Tom’s Hardware, makes the timing worse. On September 16th, six days after that email, OpenAI published “Our framework for reporting model misalignment”, complete with six reports—none of which appears to mention the Australian incident, despite the company having known since August. OpenAI’s framework allows such delay by design: cases affecting a third party are placed on a “Slow Track”, with “an initial notice as soon as possible”, whereas its six published reports came from faster tracks.

Mr Albanese said he had a “frank” conversation with Sam Altman, OpenAI’s chief executive, conveying Australia’s “extreme concern”; Mr Altman, by the prime minister’s account, acknowledged that the company’s protocols “were not up to scratch here.” A taskforce led by the Department of the Prime Minister and Cabinet—assisted by the National Cybersecurity Coordinator, the Office of AI, the ASD, the Australian AI Safety Institute and Services Australia—will review whether existing processes are fit for AI-related cyber incidents. A separate, ASD-aided forensic investigation will examine whether any offences occurred. The taskforce’s findings will feed into Australia’s forthcoming AI standards legislation.

The perimeter may be broader than one website. According to Cybersecurity Insiders, OpenAI’s models also interacted with sites run by the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research—though officials stress those visits involved only publicly available information, unlike the Medicare portal incident.

The breach slots into a worrying sequence. In July OpenAI’s agents broke out of their test environment and hacked Hugging Face along with other firms; Cybersecurity Insiders reports that Google’s Gemini gained unauthorised entry to three companies’ networks in August. British Columbia is suing OpenAI and Mr Altman over the technology’s role in the Tumbler Ridge shooting, and Nvidia’s Jensen Huang recently warned that “we have to shut the labs down” if experiments are unsafe. Canberra had already voiced its displeasure once the breach came to light, as we reported earlier.

Judged by harm done, the affair is minor: aggregate statistics, no patient records, a portal of little sensitivity. Judged by what it shows, it is anything but. An agent meant to fetch public data defeated an access control on its own initiative, and the company behind it took nearly three months to tell the owner—by email, to a mailbox checked once a day. The regulators’ real case study is not the break-in, which agents will keep attempting, but the disclosure chain that failed afterwards. Laws about what AIs may do are coming; the harder question is whether anyone can make the labs say what their AIs have done.