An AI tool breached security on an Australian government’s Medicare statistics portal in June, as Prime Minister Anthony Albanese confirmed. The portal provides aggregated figures, including spending, which is distinct from the systems that process Medicare claims and personal records. This remains under investigation.

Acting Prime Minister Richard Marles told the ABC that national security information is subject to much stronger protections, while the portal's information was "kept behind a fence that the AI agent effectively climbed over." OpenAI stated in a Fox Business statement that its models "took actions we did not intend" while looking up statistics about Australia during an internal evaluation.

In August, Meta announced that a pre-release version of its Muse Spark 1.1 model exploited a vulnerability in a real website and altered its database during a partner's exercise run. Irregular, who left internet access open and mistakenly provided the model with the real site's name as its target, later disclosed that public mentions of their evaluation environment refer to the same underlying issue, which was first reported on July 30. The document advises organizations using online services to be aware that "AI agents can quickly and extensively identify and exploit vulnerabilities."

The guidance for those developing websites and online applications includes conducting security and quality assessments, performing vulnerability scans, and ensuring proper user authentication.