After another autonomous AI hack - one that took three months for affected agencies to be alerted - Australia is pushing for accountability from OpenAI.

In June 2026, an OpenAI agent infiltrated the Australian government’s Medicare Statistics Reporting Service portal without being directly told to do so. The hack reportedly did not include sensitive information, but the agent accessed both public and non-public information. Even looking past the primary concern of a self-directed artificial intelligence (AI) agent breaking into the systems of a federal agency (which may be the first case of this ever happening) much of the uproar about the hack comes from the fact that the agency in charge of the site, Services Australia, was not made aware of the breach until September 10th, 2026. What’s more, this message was delivered in an email to the agency’s general inbox. With the additional five days that passed before the alert was given to a government minister, about three months elapsed between the intrusion and Australia’s federal leaders hearing about the incident.
On September 23rd, 2026, Anthony Albanese, the Prime Minister of Australia provided updates on the situation when talking with reporters in New York: “Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.” Albanese explained the bot was intelligent enough to look for ways around the blocks the systems had in place, and said that OpenAI “know(s) that they need to have better protocols in place… No personal information is believed to have been accessed at this stage but investigations are ongoing. Nonetheless this situation is obviously unacceptable.”
This call for better protocols for AI developers is not new. Over the past few weeks, there have been a number of headlines around autonomous AI hacks. Even then, OpenAI garnered a lot of attention for their hack on HuggingFace, an attack that “was driven, end to end, by an autonomous AI agent system”, caused by an exploitation exercise to evaluate the models’ cyber capabilities. The OpenAI hack spurred other developers to check for similar hacks, leading to Anthropic disclosing three separate instances of Claude models independently using the internet to hack into the systems of real organizations. Since then, American politicians and tech leaders alike have requested more regulation on AI, with even the CEO of Anthropic, Dario Amodei saying the company “must slow the pace at which we improve the capabilities of AI models.”
In light of the hack on the Medicare Statistics Reporting Service portal, Australia is joining others requesting better oversight and security standards for the companies behind AI manufacturers. Prime Minister Albanese shared his country’s stance when he delivered Australia’s National Statement on September 25th, 2026, in New York: “But leaders of AI companies themselves have warned of the potential risks of allowing frontier AI to develop too fast without guardrails. Recently an Artificial Intelligence Agent infiltrated an Australian Government website. This is unacceptable. And it is why Australia has been leading the way in establishing Australian Standards for AI. Standards to ensure AI will work and deliver for people – not the other way around. We can't ignore AI or prevent it. And it’s why we joined with other nations this week to call for action to shape AI development rather than be passively shaped by it.”
A good example of this action is the Senate summons issued to OpenAI CEO, Sam Altman, along with Anthropic AI Dario Amodei on September 27th, 2026. Amodei and Altman are meant to field questions about AI, data centres and data transparency in public hearings in Canberra, Australia on October 1st, 2026. A spokesperson for Senator Sarah Hanson-Young issued a statement explained that the CEOs should “face the Senate’s questions and have an honest conversation about what effective, lasting regulation of this industry should like”, particularly in reference to the “serious questions for Sam Altman to answer about the Open AI hack of Australian government websites”. While Anthropic and OpenAI have declined the invitation for this week’s hearings (both companies expressed that the time frame between the initiation and the hearings was too short), OpenAI agreed to remain in contact should another hearing be scheduled, with their Chief Strategy Officer attending a different hearing on Artificial Intelligence on October 6th, 2026. Representatives from Anthropic are also meant to attend a hearing in Australia around that time.
Even with the first hearing being postponed, OpenAI has responded to the outcry from Australia. OpenAI posted an article, “How we will do better for Australia” on September 28th, 2026. There, the tech giant breaks down all the federal Australian sites that were accessed by their agents acting autonomously - the Australian Institute of Health and Welfare, the Victorian Department of Health, Services Australia, and the NSW Bureau of Crime Statistics and Research (BOSCAR). According to the post, the intrusion occurred when they tested “an experimental, internal-only OpenAI model that was not intended for public release”, one “without the full set of safeguards used in our publicly available products.” This is not dissimilar to the circumstances behind OpenAI’s other hacks by self directed agents - the Hugging Face hack was also the result of an exercise for the AI models, where access to the internet was limited through an internally hosted third-party software.
Open AI maintains that there were no medical records breached by the agent - but does admit that “our models accessed Australian government websites in ways they were not authorised to. We should have handled our response better. We are sorry and working to do better in the future.” They explain the gap between the occurrence of the hack and the notification of Services Australia as a misstep in their investigation: “Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged. Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date.”
In addition to working closely with the Australian government, OpenAI has also agreed to provide resources to help the hacked agencies evaluate and understand the impact, to establish a taskforce to help Australians draft appropriate policy in response to advancements in AI agents, and provide financial assistance for fortifying Australian cybersecurity and critical infrastructure as part of their goal “to rebuild trust with the Australian people.” Most significantly, perhaps, is that the company has also paused training on their most advanced AI models - which aligns with the bigger conversation about slowing down AI development. The pause is only temporary - OpenAI plans to “resume training them only when we are confident that we have additional safeguards in place, which we are working on now” - but hopefully this break will be enough for the company to prevent this type of hack from happening again.