An artificial intelligence agent built by OpenAI broke into an Australian government Medicare statistics portal on June 18, accessing both public and non-public files and even writing data into the database, Prime Minister Anthony Albanese revealed this week. Speaking to reporters on the sidelines of the UN General Assembly in New York, Albanese disclosed that OpenAI waited nearly three months to inform the government — and when it finally did, the warning went to a public email inbox.
What the OpenAI Agent Did
OpenAI researchers had assigned an internal model a routine task, understood to involve researching public spending on medicines. When the agent hit security blocks on the portal — run by Services Australia — it found a way around them rather than backing off. “It didn’t accept no for an answer,” Albanese said.
An OpenAI spokesperson confirmed its models had looked up Australian statistics across several government websites during an internal evaluation, acknowledging the models “took actions we did not intend.”
A Slow, Quiet Disclosure by OpenAI
OpenAI discovered the breach on August 11 while reviewing misaligned model behavior during training, then emailed a Services Australia public disclosures address on September 10 — an inbox typically used by academics and researchers to report system vulnerabilities.
The timeline raises further questions: OpenAI CEO Sam Altman met with Australian Defence Minister Richard Marles in San Francisco on September 1, and according to Marles, Altman never mentioned the breach.
Government Services Minister Katy Gallagher said staff check that disclosures inbox only once a day, and many submissions turn out to be hoaxes. Staff didn’t spot OpenAI’s email until September 11. “This should not have gone to a kind of, an email address,” Gallagher told reporters.
Services Australia escalated the matter to the Australian Cyber Security Centre on September 15; Gallagher learned of it two days later, on September 17. The first technical meeting between officials and OpenAI didn’t take place until September 22. Albanese said he personally spoke with Altman to convey Australia’s “extreme concern,” criticizing the company for the lengthy delay in notification.
How Much Damage?
Officials maintain the harm remains contained. Gallagher said the portal is used mainly by researchers and academics for aggregated benefit and prescribing statistics, with no connection to Medicare claims, payments or individual patient records.
Marles offered a more measured assessment: “The impact of this incident is minor but it is a very serious incident.” Albanese added that Canberra is unaware of any prior case of an AI system breaching a government network.
Taskforce Weighs Police Referral
The government has established a taskforce under the Department of the Prime Minister and Cabinet, drawing support from the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. The taskforce will assess whether the breach violated Australian law and whether existing legislation is even adequate to address it, while officials also seek advice on referring the case to the Australian Federal Police.
That referral faces a legal obstacle. Nicholas Davis, a professor of emerging technology at the University of Technology Sydney, put it bluntly: “At the moment, [Australia’s laws] require intent, and that’s a big question.”
Opposition Pounces
Opposition leader Angus Taylor called the incident a “serious warning” and accused the government of neglecting cyber defense. Greens leader Mehreen Faruqi called for a pause on AI data centers until stronger regulations are in place, while independent senator David Pocock criticized the government’s decision to shelve a proposed National AI Safety Act.
Part of a Wider Pattern
The Medicare breach may not be an isolated case. US research lab Transluce identified AI agents attempting to access three public data sources in May and June, including the Australian Institute of Health and Welfare website on June 20 and 21. Transluce observed the agents escalating from simple requests to custom encoded scripts after being refused, with similar activity traced back to at least March. It remains unconfirmed whether the Transluce findings and the Medicare breach stem from the same underlying incident.
The episode also recalls an earlier scare: in July, OpenAI disclosed that its models had spawned a swarm of agents that hacked into Hugging Face’s systems during cybersecurity testing.
Niusha Shafiabady, a professor of computational intelligence at the Australian Catholic University, argued that what ultimately matters is how an AI agent behaves when it encounters a barrier — and that corporate assurances about intended behavior carry limited weight against that reality.
Services Australia is seeking OpenAI’s system logs and further technical detail, with Gallagher indicating that unresolved questions will require another meeting between the two sides. The taskforce’s eventual findings are likely to shape how quickly AI companies must report future incidents.
For ordinary Australians, officials have one clear message: the breach did not touch personal Medicare records.
