Prime minister Anthony Albanese says OpenAI did not alert the government until almost three months after one of its AI agents got around blocks on a Medicare statistics portal, and even then only by emailing a public mailbox
The Australian government has set up a taskforce to review how it responds to artificial intelligence (AI)-related cyber incidents, after an OpenAI agent gained unauthorised access to a Medicare website run by Services Australia.
Speaking to reporters in New York on Wednesday local time, prime minister Anthony Albanese said the incident took place on 18 June, when OpenAI’s research team used an internal model to search the internet for information on public spending on medicines.
“There were blocks clearly which were coming back telling the AI agent, ‘no’,” he said. “The AI agent found a way around those blocks. Didn’t accept ‘no’ for an answer, if you like.”
The agent went on to reach public and non-public files on the Medicare Statistics Reporting Service portal. Services Australia has also noted that the agent wrote files to an internal server.
No personal information is believed to have been accessed, and the evidence so far points to no broader compromise of the Services Australia network, Albanese said. The public-facing portal held non-sensitive Medicare data, such as spending statistics.
Albanese said he called OpenAI CEO Sam Altman on Wednesday to convey Australia’s “extreme concern” and his disappointment that “it took the company way too long to inform the government what had occurred”.
The first notification did not arrive until 10 September, 84 days after the incident. “The notification was an email sent to just the public mailbox,” he said.
OpenAI became aware of the incident on 11 August, during a review of misaligned model activity in training, according to a timeline published by ABC News. Altman met deputy prime minister Richard Marles in San Francisco on 1 September, but Marles has said the breach was not disclosed.
The email went to an address researchers use to report weaknesses in Services Australia’s systems. The agency passed it to the Australian Cyber Security Centre, part of the Australian Signals Directorate (ASD), on 15 September and told Katy Gallagher, minister for government services, two days later.
In a statement, OpenAI said its models “took actions we did not intend” while looking up statistics about Australia during an internal evaluation. The company said its review found no sign of patient records being accessed. What the models did reach included aggregate health statistics and internal file names.
“I think OpenAI know that they need to have better protocols in place,” Albanese said when asked whether the company could still be trusted as a partner, including on datacentres.
Review and referralThe taskforce, led by the Department of the Prime Minister and Cabinet, will draw on the National Cyber Security Coordinator, the Office of AI, ASD, the Australian AI Safety Institute and Services Australia.
In the terms of reference released on Thursday, the taskforce is expected to recommend reporting requirements for AI-driven cyber incidents and obligations on AI companies to notify and cooperate, and to consider whether current offences and penalties are an adequate deterrent.
The incident will also go to parliament’s Joint Select Committee on Artificial Intelligence. The government is seeking advice on whether any offences were committed and whether to refer the matter to the Australian Federal Police (AFP).
A forensic investigation supported by ASD is also examining whether other systems were hit. Albanese named three that may have been: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.
Marles later confirmed the agent had interacted with all three sites in June, but said those interactions were “entirely normal and public information was accessed”.
Pressed on whether Australia’s security agencies had missed the intrusion, Albanese noted the portal was “not a security website”. Earlier in the press conference, he said the government “could not find precedent” for the incident.
‘It scaled the fence’Speaking in Sydney on Thursday, Marles, who is acting prime minister while Albanese is abroad, said the agent had engaged in “misaligned behaviour”, noting that “it asked a question, the information was not given and rather than leaving at that point, it scaled the fence”.
He put the impact at “relatively minor” but called the incident “a salutary warning” about the technology being developed without safeguards in place.
He also defended the government’s timing, saying that going public without all the facts at hand would have been reckless.
Gallagher, whose portfolio covers Services Australia, was also questioned over the agency’s handling of OpenAI’s email. “That email address is looked at once a day,” she said of the inbox that received it, adding that it “sometimes gets a number of notifications, sometimes many of them are hoaxes”.
OpenAI did not provide a technical briefing on the agent’s activity until 22 September, she said.
Gallagher said the portal had been protected by anti-bot measures and that OpenAI’s email had flagged a vulnerability in it. “It is a legacy system… and it is being moved to data.gov.au, so we won’t be reactivating it,” she said.
She is also considering whether to bring forward cyber security upgrades at Services Australia, funded with A$160m over four years in the May budget, and said other legacy public-facing government websites could be shut down.
Not the lastDavid Rajkovic, regional vice-president for Australia and New Zealand at data security company Rubrik, said the breach against Medicare is just the latest example of AI agents going rogue.
He noted that the latest incident, along with the Hugging Face breach earlier this year, shows that frontier models can sustain complex cyber operations, discover novel attack paths and move across real-world systems in pursuit of a narrow objective.
“The genie is out of the bottle when it comes to AI agents and, the truth is, Australia is not fully prepared to deal with the risk agents pose. Our readiness posture is lagging. Far too many organisations are relying on prevention strategies and legacy data protection systems to solve for a very modern problem,” he added.
In July, OpenAI admitted that a combination of its models, including GPT-5.6 Sol and a more capable pre-release model, had breached Hugging Face’s systems during an internal cyber security test. With some safeguards switched off, the models broke out of their test environment to hunt for benchmark answers in Hugging Face’s production database.
Anthropic and Meta have since said their own models hacked real-world systems during pre-deployment testing. OpenAI has not said whether the same models were involved in the Hugging Face and Medicare incidents.
Albanese called the Medicare incident “a clear illustration of why we are moving to establish Australian standards for AI”.
Asked how much of a shock the breach had been, Albanese said: “It was a shock that it occurred, because it was real and serious. But it also, I think, was something that had been predicted, including by the AI companies themselves.”
Read more on Data breach incident management and recovery| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | OpenAI's breach of Australian health department website prompts rebuke from Albanese | 0 | 8.28 | 24-09-2026 |
| 2 | OpenAI Agent Breached Australia’s Medicare Data Portal, Government Says | 0 | 5.62 | 24-09-2026 |
| 3 | Australia's prime minister slams OpenAI after its agent hacked government website | 0 | 5.95 | 24-09-2026 |
| 4 | Американский ИИ взломал сайт правительства Австралии | 0 | 10.95 | 24-09-2026 |
| 5 | ABC: ИИ-агенты OpenAI взломали два правительственных сайта в Австралии | 0 | 11.32 | 02-10-2026 |
| 6 | OpenAI, Anthropic CEOs called to appear at Australian AI probe over health database breach | 0 | 9.83 | 28-09-2026 |
| 7 | OpenAI apologies for Australian government website hack, pledges to rebuild trust | 0 | 7.03 | 29-09-2026 |
| 8 | OpenAI: KI-Agent hackt australisches Gesundheitsportal, scharfe Kritik an Altman | 0 | 14.28 | 24-09-2026 |
| 9 | Американская OpenAI создала рабочую группу после взлома госпортала в Австралии | 0 | 14.57 | 29-09-2026 |
| 10 | ANZ firms put data foundations before agentic AI | 0 | 7.84 | 10-09-2026 |