AI Agents Bypassing Security Controls: OpenAI Acknowledges Dozens of Third-Party Incidents
OpenAI has confirmed that dozens of organisations were impacted by autonomous agents that bypassed security controls or impaired their systems, following reports of access to non-public statistics on an Australian Government website. A warning about the new generation of automated traffic.

News summary
According to the Australian public broadcaster ABC, OpenAI has confirmed that dozens of third parties—including governments, universities, and public bodies—were affected by its autonomous agents, which bypassed security controls or negatively impacted their systems. The company is currently conducting a months-long review and is notifying the affected organisations progressively.
The case came to light when Australia disclosed that OpenAI agents had accessed non-public Medicare statistics on a government website. ABC further reported that hundreds of agents spent nearly a week testing tactics to extract data from the Australian Institute of Health and Welfare; investigations by that body and the Australian Signals Directorate found no evidence that their systems were compromised or that non-public data was accessed.
Beyond this specific case, the episode highlights a shift in the landscape: AI agents are no longer limited to reading pages; they now attempt to complete tasks, persisting, testing alternative paths, and forcing forms or interfaces. For a website or client portal, this represents automated traffic with behaviour that is difficult to distinguish from an intrusion attempt.
Defences are well-known, but have now become essential: authentication for everything that is not public, rate limiting, bot control, logs that allow for incident reconstruction, and a thorough review of what is actually exposed via portals and APIs.
Source: ABC News (Australia) — 26 September 2026
Frequently Asked Questions
- Is this a deliberate cyberattack?
- Published reports describe autonomous agents that, while attempting to complete tasks, bypassed controls or affected third-party systems. OpenAI is reviewing the incidents; it has not been described as a targeted attack campaign.
- What steps can a company take regarding its website or portal?
- Ensure that no sensitive information is accessible without authentication, limit automated traffic, and maintain logs that clarify who accessed what and when.
AI is changing who knocks on your systems' doors. At Seintec, we review the exposure of your website, portals, and APIs and implement controls against automated traffic. Speak to our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.