How an OpenAI ‘agent’ hacked Australia’s Medicare and what that meansOpenAI 的“代理”如何入侵澳大利亚的医疗保险系统,以及这意味着什么
Incident highlights growing concerns about AI’s impact on cybersecurity and AI disclosure procedures, say experts.

Incident highlights growing concerns about AI’s impact on cybersecurity and AI disclosure procedures, say experts.
OpenAI CEO Sam Altman arrives to attend a Security Council meeting on AI, at the UN headquarters in New York, US, September 23, 2026 [Angela Weiss/AFP]
Australian authorities have raised the alarm after OpenAI-powered models hacked into a government health data system in June, slipping past its digital defences and accessing files without authorisation.
This is the first publicly known case of artificial intelligence (AI) “agents” – AI-powered software systems that can carry out tasks autonomously – breaking into a government website, and the latest of several AI breaches of external systems.
list 1 of 3 As AI leaders warn of catastrophe, US and China shun slowdown calls
list 2 of 3 What’s the US–China AI ‘hotline’ that Trump plans to pitch to Xi Jinping?
list 3 of 3 US lawmakers propose sweeping AI restrictions with superintelligence ban
The disclosure comes as top AI firms warn of the risk of humans losing control of AI, calling for its development to slow to a pace that allows it to be safely regulated. Global powers must cooperate to ensure this, they have said.
A research scientist at AI firm Anthropic, Evan Hubinger, went so far as to say he believes there is a greater than 10 percent chance AI could “kill all humans” within a decade.
Addressing the United Nations Security Council on Wednesday, OpenAI CEO Sam Altman said there is a risk of AI moving “so fast that people can no longer follow what’s happening or intervene when needed”.
“This would obviously be terrible,” he said. “And we should not train models that we cannot make an extremely strong case that we will be able to keep under human control.”
What do we know about the AI breach in Australia?
Australian Prime Minister Anthony Albanese revealed the breach on Wednesday , saying an OpenAI agent had made its way into the public-facing medical statistics portal of Medicare, the country’s universal health insurance system, on July 18.
When OpenAI accessed the government portal while conducting research on public medical spending, Albanese said the AI agent circumvented “blocks” that should have prevented it from breaking into the portal.
“The AI agent found a way around those blocks – didn’t accept no for an answer,” said Albanese.
Deputy Prime Minister Richard Marles said the information the OpenAI agent accessed was “not particularly sensitive” and was later publicly released.
Still, Albanese called the situation “obviously unacceptable” and said Australia had relayed its “extreme concern” to OpenAI, which had failed to notify the government of the breach until September 10.
Albanese also said several other government websites may have been affected by rogue OpenAI agents, though he did not confirm any other breaches.
He added that an inquiry into the breach would look at how Australian security agencies missed it initially and whether criminal charges could be brought against OpenAI.
Australia’s Government Services Minister Katy Gallagher, right, addresses the media alongside Deputy Prime Minister Richard Marles in Sydney, Australia, September 24, 2026 [Hollie Adams/Reuters]
How has OpenAI responded?
In a statement, OpenAI said it had “identified activity involving several Australian government websites and services as our models attempted to look up answers” and “took actions we did not intend”.
The company said the incident occurred as its models searched for statistics on medical spending, and that they are not believed to have obtained personal medical records.
OpenAI learned of the incident in August only as it conducted a review of “misaligned model activity”, it added.
Last week, OpenAI said it had put in place a new system to monitor, probe and disclose cases of “misalignment”. That includes instances of AI models that operate “without authorisation, coordinate with other models, or evade oversight”, it said.
Have there been previous AI breaches?
Yes. The Australia data breach is the latest of several instances in which AI agents belonging to OpenAI, Google or Anthropic have accessed external systems without authorisation.
In July, OpenAI reported that two of its most advanced AI models had broken out of a controlled test and hacked another AI company , Hugging Face. OpenAI later said it had detected its AI models communicating with each other and gaining internet access without authorisation months before that hack occurred.
In August, rival Meta AI said its AI model had hacked another company during cybersecurity testing. It said the model made changes to the internal systems of the hacked company, which it did not name, after accessing the public internet because of an error in the setup of its testing environment.
What does this mean for AI safety?
Maurice Chiodo, an Australian mathematician who works at Cambridge University’s Centre for the Study of Existential Risk, told the Reuters news agency the breach appeared to be “a significant escalation in seriousness from similar incidents we have seen in recent months”.
Experts say the Australia data breach highlights the growing dangers AI poses to cybersecurity as well as possible gaps in monitoring and disclosure capabilities.
“The important matter here is not what OpenAI says its agent can do, it is what the agent actually does when it hits a barrier,” Niusha Shafiabady, a professor of computational intelligence and head of the IT discipline at the Australian Catholic University, said in comments published by science news portal Scimex.
“The deeper technical risk is that autonomous AI does not always know when it is wrong, and humans may not be able to see why it made a decision,” added Shafiabady. “Without strong verification and hard boundaries, probabilistic errors can quietly become operational failures.”
Raffaele Fabio Ciriello, a senior lecturer in business information systems at the University of Sydney Business School, said OpenAI’s delay in reporting the breach was “concerning”.
“The incident occurred in June and only came to light months later,” said Ciriello. “Even if OpenAI did not detect the activity immediately, that still points to weaknesses in detection, escalation, and external notification.”
专家表示,这起事件凸显了人们对人工智能对网络安全和人工智能信息披露程序的影响日益增长的担忧。
OpenAI 首席执行官 Sam Altman 于 2026 年 9 月 23 日抵达美国纽约联合国总部,出席安理会人工智能会议。[Angela Weiss/AFP]
澳大利亚当局发出警报,称 OpenAI 提供的模型在 6 月份入侵了政府的健康数据系统,绕过了其数字防御措施,未经授权访问了文件。
这是人工智能(AI)“代理”(能够自主执行任务的AI软件系统)入侵政府网站的首例公开案例,也是AI入侵外部系统的最新一起案例。
列表 1/3:人工智能领袖警告灾难之际,美国和中国却拒绝放缓发展步伐
列表 2/3:特朗普计划向习近平提出的美中人工智能“热线”是什么?
美国三位议员提议对人工智能进行全面限制,包括禁止超级智能,名单如下。
此次披露正值顶尖人工智能公司警告人类可能失去对人工智能的控制之际,他们呼吁放缓人工智能的发展速度,使其能够得到安全监管。这些公司表示,全球大国必须合作确保这一点。
人工智能公司 Anthropic 的研究科学家 Evan Hubinger 甚至表示,他认为人工智能在十年内“杀死所有人类”的可能性超过 10%。
OpenAI 首席执行官 Sam Altman 周三在联合国安理会发表讲话时表示,人工智能发展速度过快存在风险,“以至于人们无法再跟上形势或在需要时进行干预”。
“这显然会很糟糕,”他说。“我们不应该训练那些我们无法充分证明能够始终处于人类控制之下的模型。”
我们对澳大利亚的人工智能安全漏洞了解多少?
澳大利亚总理安东尼·阿尔巴尼斯周三披露了这起安全漏洞事件,称 OpenAI 的一个代理程序于 7 月 18 日入侵了该国全民医疗保险系统 Medicare 的面向公众的医疗统计门户网站。
阿尔巴内塞表示,OpenAI 在对公共医疗支出进行研究时访问了政府门户网站,人工智能代理绕过了本应阻止其入侵该门户网站的“障碍”。
阿尔巴内塞说:“人工智能代理找到了绕过这些障碍的方法——不接受‘不’的答案。”
副总理理查德·马尔斯表示,OpenAI 代理获取的信息“并不特别敏感”,后来已公开发布。
尽管如此,阿尔巴尼斯称这种情况“显然是不可接受的”,并表示澳大利亚已向 OpenAI 表达了“极度关切”,OpenAI 直到 9 月 10 日才将此次违规事件通知政府。
阿尔巴尼斯还表示,其他几个政府网站可能也受到了 OpenAI 恶意代理的影响,但他没有证实任何其他安全漏洞。
他还补充说,对此次安全漏洞的调查将着眼于澳大利亚安全机构最初是如何漏掉的,以及是否可以对 OpenAI 提起刑事诉讼。
2026年9月24日,澳大利亚政府服务部长凯蒂·加拉格尔(右)与副总理理查德·马尔斯在悉尼向媒体发表讲话。[Hollie Adams/路透社]
OpenAI对此作何回应?
OpenAI 在一份声明中表示,“我们的模型在尝试查找答案时,发现了涉及多个澳大利亚政府网站和服务的活动”,并且“采取了我们意想不到的行动”。
该公司表示,该事件发生时,其模型正在搜索医疗支出统计数据,但据信他们并未获取个人医疗记录。
OpenAI补充说,该公司直到8月份对“模型活动错位”进行审查时才得知此事。
上周,OpenAI表示已建立一套新系统,用于监控、调查和披露“不协调”案例。该公司称,这包括人工智能模型“未经授权运行、与其他模型协调运行或逃避监管”的情况。
之前发生过人工智能安全漏洞事件吗?
是的。澳大利亚的数据泄露事件是近期发生的几起事件中的最新一起,这些事件都表明,OpenAI、谷歌或Anthropic等公司的AI代理未经授权访问了外部系统。
今年7月,OpenAI报告称,其两款最先进的AI模型突破了受控测试,并入侵了另一家AI公司Hugging Face。OpenAI后来表示,早在黑客攻击发生数月前,他们就已检测到其AI模型之间存在相互通信,并在未经授权的情况下获取了互联网访问权限。
8月份,竞争对手Meta AI表示,其人工智能模型在网络安全测试期间入侵了另一家公司。该公司称,由于测试环境设置错误,该模型访问了公共互联网,并对被入侵公司(未透露公司名称)的内部系统进行了更改。
这对人工智能安全意味着什么?
在剑桥大学生存风险研究中心工作的澳大利亚数学家莫里斯·基奥多告诉路透社,此次泄露事件“与我们近几个月来看到的类似事件相比,严重程度显著升级”。
专家表示,澳大利亚的数据泄露事件凸显了人工智能对网络安全日益增长的威胁,以及监控和披露能力方面可能存在的漏洞。
“这里重要的不是 OpenAI 声称其代理能做什么,而是代理遇到障碍时实际会做什么,”澳大利亚天主教大学计算智能教授兼 IT 学科负责人 Niusha Shafiabady 在科学新闻门户网站 Scimex 上发表的评论中说道。
沙菲亚巴迪补充道:“更深层次的技术风险在于,自主人工智能并非总能知道自己何时犯错,而人类也可能无法理解它做出决策的原因。如果没有强有力的验证和严格的界限,概率性错误可能会悄无声息地演变成运行故障。”
悉尼大学商学院商业信息系统高级讲师拉斐尔·法比奥·西里洛表示,OpenAI 延迟报告此次数据泄露事件“令人担忧”。
“这起事件发生在6月份,但几个月后才被曝光,”Ciriello说。“即使OpenAI没有立即检测到该活动,这也仍然表明其在检测、升级和外部通知方面存在缺陷。”