The unauthorised access by an OpenAI artificial intelligence agent to an Australian government health statistics portal has raised fresh questions about how organisations control what autonomous AI systems can access as companies increasingly deploy agents to carry out tasks across networks and applications.
The incident occurred on June 18 when an OpenAI agent, carrying out research into public medicine spending, gained unauthorised access to the Medicare Statistics Reporting Service portal operated by Services Australia. The agent accessed public and non-public files, although Australian authorities and OpenAI have said there is no evidence that individual patient records were accessed.
The Australian government has launched a forensic investigation into the incident, including how the agent bypassed restrictions and whether other government systems were affected. OpenAI told the government that its models had interacted with several Australian government websites during an internal evaluation and had taken actions the company did not intend.
Jody Brazil, CEO of cybersecurity company FireMon, said the incident necessitated a basic question enterprises will need to address as AI agents are given greater autonomy.
“What can those agents actually access, and how do you know those boundaries are working? A legitimate task should never be treated as permission for unrestricted access,” Brazil said.
Australian officials said the OpenAI agent had been given what they described as a benign research task. After it was unable to obtain the information it sought through the normal interface, the agent found another way to access the portal.
Acting Prime Minister Richard Marles described the behaviour as unauthorised and said the agent had accessed aggregated medical statistics rather than individuals’ health information.
Brazil said organisations deploying AI agents need visibility into the connectivity available to them and should remove permissions that are no longer required.
“Network security policy management is an essential part of answering that question. Organisations need to understand permitted connectivity, remove access that is no longer necessary and validate that policy changes preserve the intended boundaries,” he said.
The issue is becoming more significant as AI agents move beyond answering questions and are given the ability to browse websites, execute code, interact with applications and carry out multi-step tasks with limited human intervention.
Unlike conventional software, such systems can determine intermediate steps required to achieve an assigned objective. That creates an additional security challenge when an agent encounters access restrictions or unexpected system behaviour.
Brazil cautioned that network controls alone would not prevent every problem involving autonomous agents, particularly where vulnerabilities exist at the application or authorisation layer.
“The technical findings will determine which safeguards failed here. Network controls alone cannot address every application vulnerability or authorisation failure,” he said.
OpenAI became aware of the Australian incident in August while reviewing what it said as misaligned model activity and notified Services Australia on September 10. Australian Prime Minister Anthony Albanese has criticised the delay in reporting the incident.
Brazil said enterprises should use the incident to review why systems and applications are accessible, who authorised that access and when those permissions were last checked.
“Those are basic operational questions that become more urgent as AI adoption grows,” he said.





