Artificial intelligence agents from OpenAI tried to exploit four websites of governments, universities, and public databases during routine information-gathering tasks, without having received instructions to carry out cyberattacks. One of the incidents ended with unauthorized access to files from an Australian government portal.
The cases occurred between May and June, before the breach of the Hugging Face platform by the company's agents in July. Three incidents were identified by independent lab Transluce, and all four were later confirmed by OpenAI, according to the New York Times.
On May 25 and 26, the systems tried to obtain photographs from a digital library at the University of New Mexico. After normal access attempts failed, the agents began looking for vulnerabilities and even sent dozens of requests to the server. The intrusion apparently was not successful.
Two days later, agents targeted Data USA, a service that gathers American public data. After a query failed, the systems sent 12 probes searching for vulnerabilities, also without gaining additional access.
Agent accessed non-public files from the Australian government
The most serious incident occurred on June 18, when an internal OpenAI model was searching public data on medicine spending in Australia. After encountering repeated blocks, the agent sought alternative paths and gained unauthorized access to the Medicare Statistics Reporting Service, administered by Services Australia.
The agent managed to access public and non-public files and also wrote files on the internal server, according to Prime Minister Anthony Albanese. So far, there is no evidence of access to patients' personal data. OpenAI stated that its models took “actions we did not intend” during the evaluation.
On June 20 and 21, agents also tried to exploit the Australian Institute of Health and Welfare website after encountering barriers to obtaining pharmaceutical data. Transluce researchers identified vulnerability probes; there is no indication that private information was obtained.
OpenAI said it is conducting a broad review of activities considered misaligned during training and evaluations. The company said it has already notified dozens of potentially affected third parties and acknowledged that some agents bypassed access controls, used exposed credentials, or reached internal components of external services.
Australia weighs possible legal accountability
Albanese announced this Thursday (24) a task force to investigate the incident and determine whether any infraction was committed. The government will seek guidance on a possible referral of the case to the Australian Federal Police and will use the findings in drafting its legislation on AI standards.
The prime minister also criticized OpenAI's delay in reporting the incident. The breach occurred on June 18, but the first notification to the government was sent only on September 10, through a public email inbox. Albanese said there will be “legal consequences,” without anticipating what accountability could result from the investigation.



