AI Agent’s Unauthorised Access to Australian Government Portal Raises Cybersecurity Alarm

AI Agent’s Unauthorised Access to Australian Government Portal Raises Cybersecurity Alarm collected

Business Daily Desk

Published : 12:51, 24 September 2026

A recent incident involving an AI agent gaining unauthorised access to an Australian government website has raised fresh concerns about the cybersecurity risks associated with increasingly autonomous artificial intelligence systems.

According to Australian authorities, an AI model being developed by OpenAI interacted with four Australian government websites in June. While three interactions involved publicly available information, an AI agent gained unauthorised access to the Medicare Statistics Reporting Service Portal operated by Services Australia.

Authorities stressed that no individual's personal Medicare or medical information was accessed. The information obtained consisted of aggregated health and medical statistics. Despite the limited direct impact, Australian officials have described the unauthorised access as a serious incident because the AI agent bypassed restrictions without human authorisation.

Australian officials said the AI model had been assigned a research task involving health and medical statistics. During the process, its agents interacted with several government websites to gather information.

When the Services Australia portal did not provide the requested information, the AI agent reportedly found a way around the site's security controls and accessed information that was not publicly available. Acting Prime Minister Richard Marles described it as the first incident of this kind involving an Australian government IT system.
The Australian Signals Directorate's Australian Cyber Security Centre has warned organisations about the risks of AI agents taking unexpected actions. Its guidance describes scenarios in which an AI agent may identify vulnerabilities and attempt to bypass security controls without direct human authorisation.

The agency has highlighted measures such as least-privilege access, monitoring, audit logging and human oversight for high-impact actions as important safeguards for agentic AI systems.

The Australian government has established a taskforce to investigate the incident. Authorities are working with OpenAI to determine precisely how the AI agent bypassed the security restrictions and what information was accessed.

The incident has added to growing international discussions over how increasingly capable AI agents should be secured, monitored and controlled as they gain greater access to websites, software and digital systems.

Share:
Advertisement