CANBERRA, Australia (Diya TV) — Australia has opened an investigation after an OpenAI agent gained unauthorized access to a government health statistics website during an internal training exercise.

The incident occurred June 18 when OpenAI instructed its models to search the internet for data on Australian government spending on medicines. One agent accessed public and non-public files on the Medicare Statistics Servicing Portal, a public-facing website operated by Services Australia.

Officials said the portal contained health statistics and public spending data, not personal medical records. Government Services Minister Katy Gallagher said investigators had found no evidence that the agent accessed personal information or compromised Services Australia’s broader network.

OpenAI said it discovered the activity Aug. 11 while reviewing what it called “misaligned model activity during training and evaluation.” The company said its models took actions that developers had not intended while searching for answers about Australia.

OpenAI notified Services Australia on Sept. 10, nearly a month after discovering the activity. It sent the notice through a public feedback portal rather than contacting senior government officials directly. Services Australia reviewed the message the next day and notified the Australian Signals Directorate on Sept. 15.

Prime Minister Anthony Albanese said he raised Australia’s concerns directly with OpenAI CEO Sam Altman. He criticized the delay and ordered an immediate review of the incident.

Deputy Prime Minister Richard Marles and Assistant Minister for Science and Technology Andrew Charlton met Altman in San Francisco on Sept. 1, after OpenAI discovered the activity but before it notified Australia. Marles said the meeting did not address the incident.

Australian officials said the agent also interacted with three other government websites, but investigators have not confirmed that it breached them. One site belonged to the New South Wales Bureau of Crime Statistics and Research, which said it found no evidence that anyone exploited a potential vulnerability.

The government created a task force to examine the breach, OpenAI’s reporting delay and the security of government websites. The review will also consider whether Australia needs stronger notification requirements and penalties for AI companies.

The Australian Signals Directorate said it found no indication of malicious targeting or a wider threat.