Australia says an AI agent broke into one of its government websites.
The Australian government says an autonomous agent built on OpenAI's technology breached a government website. Channel News Asia broke the story, citing officials who describe the intrusion as the work of an AI agent rather than a human operator. It appears to be one of the first times a national government has publicly pinned a breach of its own infrastructure on agentic AI software rather than a hacking group. That framing alone signals how seriously officials are treating the shift from AI agents as browsing assistants to AI agents as potential attackers.
OpenAI is one of several labs, alongside Anthropic and Google, racing to give models hands that can click, type, and navigate the web on a user's behalf. The pitch has always been productivity: let the agent book the flight, fill the form, file the ticket. An incident like this shows the same automation cuts both ways, since a tool built to act autonomously on the open web doesn't distinguish between a legitimate task and a malicious one unless something stops it.
Governments rushing to adopt AI tools might want to notice that the tools can apparently also be turned against them.