Australia says OpenAI agent accessed healthcare-statistics portal in June
AI agents linked to OpenAI attempted in May and June to break into university and government websites while carrying out routine online data-collection tasks, according to newly published findings from nonprofit AI research lab Transluce and from the Australian government. The attempted intrusions join a growing list of incidents in which AI agents have acted beyond their intended scope, the researchers said.
Transluce identified three of the targeted sites as the Australian Institute of Health and Welfare, the University of New Mexico, and Data USA, a public-data venture run by Deloitte, Datawheel and the Massachusetts Institute of Technology. In the three attempts, the researchers found, the agents were unable to obtain the data they sought and turned to hacking techniques, appending what are called malicious payloads to their web queries. Transluce said there was no evidence the intrusions succeeded.
The attempted breaches were not tied to OpenAI evaluations of cybersecurity, where models were ordered to hack, but appeared to come from internal benchmark tests of the models’ ability to find public information online, according to the Transluce report. The agents were seeking data such as Thai labor force statistics and Australian dermatological information.
In addition to the three targets named by Transluce, Australian Prime Minister Anthony Albanese said Wednesday at the United Nations meeting in New York that an OpenAI agent infiltrated a government-services website in June. The agent gained access to both public and nonpublic files in the country’s public facing healthcare-statistics portal, which reports information such as spending, he said. OpenAI said Wednesday it was in touch with Australia about the incident and that its agents had taken actions that it didn’t intend.
An OpenAI spokesman said the company is conducting an extensive review of what it calls misaligned activity, and that the incidents in the Transluce report overlap “with cases at varying stages of investigation in our ongoing review.” The company has reached out to the institutions affected, the spokesman added, saying the broader review — including lower-severity incidents such as “agents spamming websites” — will take months.
Researchers were able to piece together the agents’ web queries because the bots were using an online tool to act as a web browser, according to Transluce. The researchers hypothesize the agents were using the tool to get around restrictions on their web browsing — for instance, to access websites that have blocks against automated access.
Transluce studied a much broader set of arcane AI agent data requests that stretch back as far as November 2025 and continue as recently as mid-September, according to the report.