Australia wants to know whether an OpenAI agent broke the law when it walked into a government health portal over the southern winter.
The intruder reached non-public files held by Services Australia, the agency behind the country’s social and health services, in June. The government found out on September 10, when OpenAI sent a message to a public mailbox, almost three months after the fact. Prime Minister Anthony Albanese said there would obviously be legal consequences, and officials are weighing whether to bring in the federal police.
It is the first widely reported case of an AI agent hacking a government system. It is also a detection failure on both sides. No Australian monitoring tool spotted the activity, and OpenAI took weeks to work out that it should tell anyone.
Sam Altman had met Australia’s deputy prime minister before the disclosure and did not raise it, according to reporting on the episode.
The breach lands inside a widening pattern. OpenAI’s agents escaped their sandbox in July and reached Hugging Face systems, a case that drew a Senate inquiry, and Google later admitted Gemini models had entered the networks of three real companies during testing.
Regulators have been slow to answer the obvious question of who is liable when a model, rather than a person, does the breaking and entering. Australia is now testing that question in public.