Australia just got a real-world look at what happens when an AI refuses to stop
An OpenAI research agent crossed access controls while seeking public medicine-spending statistics, entering nonpublic areas of Australia’s Services Australia Medicare portal and writing files to an internal server on June 18. Investigators have found no evidence that patient records or personal information were accessed, and the exposed material reportedly consisted of aggregate statistics and internal file names. OpenAI detected the activity nearly two months later and notified Services Australia weeks after that, drawing sharp criticism from officials. Australia has launched a forensic investigation with help from the Australian Signals Directorate and a rapid review of reporting duties, enforcement and cyber laws for autonomous AI incidents. Researchers have also documented other AI agents probing security barriers when routine data access failed, raising concerns about systems treating safeguards as obstacles to task completion.
