NEWS EXPLAINER24 September 2026An OpenAI agent accessed secure data on an Australian health-care website, but the incident wasn’t reported for months.ByMohana Basu &Rachel Fieldhouse1Mohana BasuView author publicationsSearch author on: PubMed Google ScholarRachel FieldhouseRachel Fieldhouse is a reporter for Nature in Sydney, Australia.View author publicationsSearch author on: PubMed Google ScholarSave articleView saved researchOpenAI chief executive Sam Altman spoke at the United Nations Security Council meeting on AI in New York this week.Credit: Selcuk Acar/Anadolu via GettyThe Australian Prime Minister Anthony Albanese revealed on 23 September that an artificial-intelligence agent created by technology giant OpenAI hacked into a government health-care website in June, where it accessed private data.Researchers say this is the first instance of a frontier AI model breaching another country’s government systems. Although no personal health data are thought to have been accessed, the breach is the latest in a series of such incidents perpetrated by agents this year.How to manage AI risks while reaping the benefitsOpenAI says the hack occurred during agent training and that it is in the process of notifying third parties of potential impacts on their systems.News of the security breach comes as global leaders, including Albanese, meet in New York City for the United Nations General Assembly. China’s President Xi Jinping also met with US President Donald Trump on Wednesday for a three-day summit, at which the leaders are expected to discuss AI safety. But analysts say it is unlikely that any deals will be struck.The latest attack is not surprising and more reports of agents doing things that they shouldn’t are likely to surface, says Jonathan Kummerfeld, who studies AI and human–computer interaction at the University of Sydney in Australia. AI companies run many experiments at the same time and “they probably aren’t seeing everything these models are doing”, he adds.What did the OpenAI agent do?In a press conference in New York City, Albanese told the media that an experimental OpenAI agent with access to the Internet was carrying out research on Australian health and medical spending when the agent reportedly gained unauthorized access to the Medicare statistics reporting service. This is a public website that aggregates data on vaccinations, government spending on medical consultations and medicines, as well as organ donor register information.After being repeatedly blocked from accessing certain information that was not public, the agent was able to work around security measures to access the data, Albanese said.China wants to lead the world on AI regulation — will the plan work?The breach was not detected by the Australian government. Instead, Albanese said that OpenAI notified them by sending an e-mail to a public government e-mail address, which was “unacceptable”.Albanese announced an investigation into what happened. “There will obviously be legal consequences,” he added. OpenAI did not respond to questions about the incident.Did the OpenAI agent go rogue?In a statement, an OpenAI spokesperson said that they identified the breach in August while “conducting an extensive review of misaligned model activity” that occurred during model training. Misalignment is when AI models behave in unexpected ways that don’t align with human laws and values.During this review, the company identified activity involving several Australian government websites and services. As the AI model attempted to look up answers and available statistics for questions about Australia, it “took actions we did not intend”, the spokesperson said. The company is in the process of notifying third parties about when a potential breach of their systems occurred, they said.The incident seems to have happened at around the same time as another cybersecurity incidents involving OpenAI agents. Between May and July, while OpenAI was conducting tests of its agents in a controlled environment, the agents found ways to get around restrictions and gained access to the Internet. Hundreds of agents then targeted an open-source AI platform called Hugging Face, gaining unauthorized access to data sets and accounts.It is unclear whether the incident involving the Australian website was part of a similar test environment, but Raffaele Ciriello, who studies ethical use of emerging technologies at the University of Sydney, says it’s reasonable to assume that it was.Ciriello says that the incident isn’t a case of an AI agent going rogue; rather the agent was given instructions to find certain information and in following those instructions it found a way to gain access to non-public information. “The agent is not a legal person,” he says. The responsibility therefore falls on OpenAI and its staff who authorized, configured and supervised the system, he adds.doi: https://doi.org/10.1038/d41586-026-03024-zWhy AI companies can’t be trusted to self-regulate AI is set to completely transform cybersecurity — here’s how researchers must prepareAI companies must work with the research community to protect attribution How to manage AI risks while reaping the benefits Too dangerous to release: is Mythos the start of the restricted-AI era?SubjectsGovernmentMachine learningComputer scienceLatest on:GovernmentMachine learningComputer scienceJobs Chemistry Faculty Positions at Westlake UniversityChemistry at the School of Science is committed to fostering inclusive excellence in a variety of research and teaching activities.Hangzhou, Zhejiang (CN)Westlake UniversityPrincipal Investigators in NeuroscienceThe Chinese Institute for Brain Research, Beijing (CIBR) (https://www.cibr.ac.cn/) aims at building a vibrant interdisciplinary research program th...Beijing, China (CN)Chinese Institute for Brain Research, BeijingSenior Publisher, Computer Science JournalsJob title: Senior Publisher Locations: New York or London — hybrid working model Closing date: October 13, 2026 About Springer Nature Springer ...New York City, New York (US)Springer Nature LtdPostdoctoral AssociateJoin the Hu Lab at Rutgers Cancer Institute to study p53, cancer metabolism, tumor immunology, tumor microenvironment, and cachexia.New Brunswick, New JerseyRutgers Cancer Institute - Cancer Metabolism and ImmunologyAssociate or Senior Editor, Nature Mechanical EngineeringJob Title: Associate or Senior Editor, Nature Mechanical Engineering Location: Beijing, Shanghai and Milan - Hybrid Working Model. Closing date:...Beijing, Shanghai and Milan - Hybrid Working Model.Springer Nature Ltd