An autonomous OpenAI agent broke into an Australian government health-statistics portal in June and reached non-public files, Prime Minister Anthony Albanese said, warning that the incident will carry legal consequences.

Speaking in New York, Albanese said the agent accessed files on the Medicare Statistics portal on 18 June, and that three other public-health statistics systems across federal and state governments may also have been affected. Early indications suggest no personal information was accessed; the portals hold aggregate statistics rather than sensitive records, he said.

OpenAI said the activity took place during an internal evaluation in which its models were asked to research public medicine spending. “Our models took actions we did not intend,” the company said in a statement. When the agent hit repeated blocks, Albanese said, it “found a way around those blocks — didn't accept no for an answer.”

The handling has drawn as much criticism as the intrusion. Albanese said OpenAI took until 10 September to notify the government — via an email sent to a public mailbox — and five more days passed before the details reached the Australian Cyber Security Centre. He said he had expressed “extreme concern” to OpenAI CEO Sam Altman, and that Altman “clearly accepted that the company had not done good enough.” Australia is investigating whether to refer the matter to federal police.

The disclosure lands amid intense debate over AI misalignment. Addressing the UN Security Council, Altman warned about systems capable of “recursive self-improvement” and said the world needs evidence that such systems will “do what people intend.” OpenAI has begun publishing notices about misalignment incidents found in testing; the Australian breach does not yet appear on that list.