Australian Prime Minister Anthony Albanese called out OpenAI chief executive Sam Altman on Wednesday, Sept 23. Speaking at the United Nations General Assembly in New York, Albanese told reporters that an OpenAI agent broke into a government health data website earlier this year without permission.

Cybersecurity analysts view the incident as a highly alarming example of rogue AI models, and they mark it as one of the first high-profile cases where an AI agent actively hacked into a government portal.

For tech investors, this incident is intensifying the debate around AI safety and changing how the market evaluates regulatory risks.

OpenAI is the company behind ChatGPT. It makes money by selling paid ChatGPT subscriptions, licensing its AI models to software developers, and building custom AI tools for large businesses.

The company was privately valued at $852 billion earlier in 2026, and Altman said that going public right now would be “ill-advised” given the safety concerns circulating around the industry.

How an OpenAI agent slipped into Australia’s Medicare portal

According to ABC News, the agent was given a simple research task to find data on public medical spending. When the website blocked it from accessing certain files, the agent found a loophole instead of stopping.

Albanese said the agent “found a way around those blocks, didn’t accept no for an answer.”

It accessed both public and restricted files on the Medicare Statistics Reporting Service portal. No individual patient records were involved, but internal government files were touched, and the agent even wrote files into the system.

The time it took before the case was reported also drew criticism. OpenAI found the problem internally on Aug. 11, but did not alert Australia’s Services Australia agency until Sept. 10, and even then, only through a public email inbox, according to NPR.

A full technical briefing between OpenAI and Australian officials only happened on Sept. 22, more than three months after the breach itself.

Australia’s prime minister took the unusual step of publicly criticizing OpenAI over a three-month notification delay.

ANDREJ IVANOV / Getty Images

Why the breach matters for OpenAI investors

The biggest near-term problem is trust. Large companies considering AI agents for their own operations now have a real-world example of an agent going off-script and accessing systems it was never supposed to touch.

If corporate buyers slow down or stop their AI agent purchases out of caution, that directly threatens the revenue growth that supports OpenAI’s massive valuation.

The timing also creates headaches for the company’s public listing plans. OpenAI has been pushing toward a $1 trillion valuation before going public. A high-profile safety incident gives regulators and big institutional investors more reason to demand cleaner safety records before putting money in.

More AI Stocks:

Michael Heinrich, chief executive and co-founder of 0G Labs, an AI infrastructure company that builds safety tools for AI systems, told me in a recent interview that the industry needs a different approach.

“We need to ensure that agents are accountable, that they have guard rails, and that we have complete auditability and observability,” Heinrich said.

Where AI investment dollars are quietly rotating

Cybersecurity stocks have been climbing for weeks as investors start pricing in the cost of protecting systems from exactly this type of incident.

According to 24/7 Wall St., the Global X Cybersecurity ETF gained 10.7% between Sept. 11 and Sept.18 alone. Palo Alto Networks (PANW) and Fortinet (FTNT) posted year-to-date gains of roughly 114% and 125% during the same stretch, showing how fast money is flowing toward AI defense companies.

CrowdStrike (CRWD) chief executive George Kurtz, who co-founded the cybersecurity company in 2011 and has spent more than a decade building threat-detection tools, said “the agents are dangerous.” He also said “The agents need to be controlled.”

Related: Jim Cramer says one 28-year-old tech giant is a terrific buy

His company just posted a record $333 million in net new annual recurring revenue last quarter, a sign that businesses are already writing checks for AI security protection.

Heinrich sees the shift going even deeper, toward the software that manages which AI models a company uses and how those models are monitored.

“We would see a lot of the value accrue more at the harness orchestration layer where companies are indifferent between these different models. What I really need is better guard rails, better safety systems, better ways of managing my spend,” he told me.

What retail investors can realistically do now

Jumping into cybersecurity stocks after a big run has its own risks. Palo Alto shares fell more than 5% after beating expectations with 34% revenue growth to $3.41 billion in its fiscal fourth quarter. This happened because investors worried more about shrinking profit margins than growth, Yahoo Finance reported.

Investors who already own broad technology index funds have exposure to both sides of this trade: the AI model builders under pressure and the cybersecurity companies that are benefiting. Adjusting the balance between those two types of holdings, rather than making one big bet, is worth discussing with your financial adviser.

Heinrich believes the AI agent economy is still in its earliest stages.

“About 80% of the world has never used AI,” he said.

That suggests demand for safety tools will keep growing for years. Investors considering new positions may want to focus on companies that already have real revenue and paying customers rather than pre-IPO names that are still proving their business models.

Related: Top analyst sets outrageous Intel stock target ahead of earnings