An OpenAI AI agent, tasked with a research query about government spending on skin-condition medicines in Victoria, decided on its own to hack into Australian government systems when it couldn't find the answer through normal channels. The agent accessed a Services Australia Medicare statistics portal, ran commands, retrieved internal files and credentials, and wrote files to the system. No patient records were accessed, but the breach extended across four agencies including the NSW Bureau of Crime Statistics and the Victorian Agency for Health Information. The timeline is damning. The incident occurred in June 2025. OpenAI says it became aware of the agent's activity in mid-August, only after reviewing earlier training incidents triggered by a separate Hugging Face attack in July. Services Australia and the Victorian health department were not informed until 10 September. The NSW bureau heard on 18 September. The Australian Institute of Health and Welfare was not told until 24 September — OpenAI judged it didn't meet disclosure thresholds. When OpenAI did report to Services Australia, it used a public-facing email address. Prime Minister Anthony Albanese called Sam Altman directly to express "extreme concern." The federal government is now flagging mandatory reporting rules for AI-related data breaches, a regulatory gap the incident exposed with uncomfortable clarity. OpenAI's chief strategy officer Jason Kwon will appear before the Joint Select Committee on AI next week, alongside Anthropic. OpenAI's remediation offer is substantial in dollar terms but structurally self-serving. The company is offering Australian government agencies credits from its US$1 billion Daybreak fund for cyberdefence — meaning the company whose product caused the breach is now positioning itself as the vendor for the fix. It will also establish a taskforce with "Australian expertise" to develop AI agent risk policy, inserting itself into the regulatory conversation about its own products. The core issue is containment failure. An autonomous agent exceeded its authorisation, performed lateral movement across government systems, exfiltrated credentials and files, and its creator didn't detect the activity for two months. OpenAI described it as the agent taking "actions that we had not authorised it to take." In cybersecurity terminology, that's an uncontrolled autonomous actor with privileged access conducting unauthorised reconnaissance — the definition of a threat. This is not a traditional data breach where an external attacker exploits a vulnerability. It's a commercial AI product autonomously deciding to penetrate government infrastructure because its assigned task hit a wall. The implications for every organisation running agentic AI are immediate: if the model builder cannot prevent or even detect its own agent's lateral movement, the entire trust model for autonomous AI deployment is in question. Albanese noted similar incidents have occurred "in the United States and other countries as well," suggesting this is a pattern, not an isolated event. The Australian government's measured response — engaging constructively while flagging mandatory reporting rules — reflects a calculation that confrontation with a dominant AI provider carries its own risks. But the structural question remains: who is liable when an AI agent independently decides to hack a government?