About Research Work With Me AI News Contact
AI SAFETY

OpenAI's AI Hacked a Government System on Its Own. Here's How to Protect Yourself.

An OpenAI test agent broke into an Australian government Medicare portal without being told to, and OpenAI just shelved its next model over safety. Here’s what happened — and five ways to protect yourself when AI acts for you.

Editorial graphic reading: Nobody told it to break in. Five ways to stay safe when AI acts for you.
An OpenAI test agent went further than anyone asked. Illustration

OpenAI has canceled the launch of its newest AI model, GPT-6.1 Astra, after its own safety testing came up short. It had been expected this month.

OpenAI’s head of safety systems, Saachi Jain, told CNBC the model “didn’t quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it’s done.” In plain English: it went beyond what it was allowed to do, and it wasn’t clear enough with people about what it had done.

That decision landed days after a separate incident in Australia made it very clear why that matters.

What happened in Australia

On June 18, OpenAI was testing an experimental AI agent — an internal model, not ChatGPT and not Astra. It gave the agent a simple research task: find out how much the government spends per person on medicines for skin conditions in Victorian communities.

When the agent couldn’t easily find what it wanted, it went further. It found a way into the non-public side of a government Medicare statistics website. In OpenAI’s own words, reported by iTnews, the agent “ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files.”

Nobody told it to do that. It was still just trying to finish its homework.

OpenAI first described what was taken as only aggregate health statistics and internal file names. It later admitted the agent had also taken login credentials. Both OpenAI and the Australian government say no patient medical records were accessed.

Nobody told it to break in. It was still just trying to finish its homework.

Dr. Erin Jacques

The timeline

What we still don’t know

Big questions are still open. As iTnews reported, neither OpenAI nor the Australian government has said whose credentials were taken, what they could unlock, or whether they’ve been changed.

The Prime Minister said three other government systems may have been affected, and OpenAI has since described its agents touching three more Australian systems. A government forensic investigation is ongoing, and OpenAI’s chief strategy officer is due to face questions from a parliamentary committee on October 6.

Meanwhile, AI companies are racing to release “agents” — AI that can act for you in your email, your files, your accounts and your shopping. This incident happened inside a test lab. But it shows what an agent can do when it decides the rules are in the way.

5 ways to stay safe when you let AI act for you

  1. Give it the least access possible. If a tool lets you choose, connect only the one folder or app it needs for the job — not your whole computer or every account. Use “read only” access when the AI only needs to look, not change things.
  2. Make it ask before it acts. Keep approval turned on for anything important: buying, sending, deleting or signing up. Never let an AI agent do those things on autopilot.
  3. Protect your passwords. Use a different password for every account, a password manager, and two-factor authentication. Then if an AI — or anyone else — gets one password, it doesn’t unlock everything.
  4. Turn off training on your data. Many AI apps use your conversations to train their AI unless you switch it off. Look for settings like “Help improve our AI models” in Meta Muse or “Improve the model for everyone” in ChatGPT, and turn them off.
  5. Check what’s connected, and cut what you don’t use. Every few weeks, open your AI app’s settings and look at which accounts and apps are connected. Disconnect anything you’re not actively using. Fewer connections means less that can go wrong.

None of this means you shouldn’t use AI agents. I use them every day. It means you decide what they can touch — before they decide for you.

Inside Leveraging AI, we build with these tools the safe way: the right access, the right approvals, and nothing on autopilot that shouldn’t be.

Come build with us.

Dr. Erin Jacques

Dr. Erin Jacques is a professor of informatics at the City University of New York and the founder of Leveraging AI and ChatifyIT, where she helps people build and monetize AI-powered web apps people pay to subscribe to.