An OpenAI AI agent gained unauthorised access to a Medicare data portal while researching Australian medicine spending, prompting an investigation into whether other government systems were also affected.

Key Takeaways
- An OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service on June 18 while attempting to research Australian public medicine spending.
- OpenAI discovered the incident in August during a review of its AI models, but did not notify the Australian government until September 10, when it contacted a public service email inbox.
- OpenAI says no personal Medicare information was accessed, with the agent obtaining aggregate health statistics and file names.
- Authorities are examining whether three other systems were affected, including the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health.
- Prime Minister Anthony Albanese raised the breach directly with OpenAI CEO Sam Altman, expressing “extreme concern” about the incident and disappointment over the delay in notifying the government.
- The Australian Signals Directorate is investigating the breach, while a government task force will examine whether OpenAI broke Australian laws.
Big Number
84 days. The time between the OpenAI agent accessing the Medicare portal on June 18 and the company notifying the Australian government on September 10.
Crucial Quote
Prime Minister Anthony Albanese addressed the breach while speaking to reporters in New York on Thursday, after raising the incident directly with OpenAI chief executive Sam Altman. “It was a shock it occurred, because it was real and serious, but it also was something that had been predicted by the AI companies themselves,” he said.”OpenAI know that they need to have better protocols in place.”
Reactions from experts
Dr Shaanan Cohney, Senior Lecturer in the Faculty of Engineering and IT, The University of Melbourne
“No matter whether you attribute the carnage more to the bots or the humans, it’s clear that we as a society are not in control. The hack of the Medicare data portal is not an outlier, but rather the latest in a string of hacks that are testing the convictions of even those most sceptical of AI risks,” says Cohney.
“Yes, bots shouldn’t be given internet access during security testing; yes, the companies ought to do a better job of their safeguards; yes, this latest hack was the result of security lapses on the part of the government. But human history is littered with disasters in which everyone knew what ‘ought’ to have been done to deter them. While we do not know which failures will be the ones to cause the most harm, not knowing must not lead to inaction.”
Professor Karin Verspoor, Dean of the School of Computing Technologies, RMIT University
“The fact that the crawlers were able to access private files suggests that the security settings on the websites need to be reviewed to prevent unauthorised access,” says Verspoor.
“An important part of these systems is what is called the Robots Exclusion Protocol, where a website can signal to a crawler that they don’t want certain parts of the site to be accessed. In this case, OpenAI has very likely ignored any such restrictions set up by the government websites, and simply hoovered up everything that could be accessed.”
Dr Rob Nicholls, Senior Research Associate Faculty of Arts and Social Sciences, The University of Sydney
“An AI agent broke into a government Medicare system and helped itself to non-public files, and OpenAI sat on that for three months before telling us. If a person had done this, we’d call it hacking. The fact it was an AI agent doesn’t make it less serious, it makes our disclosure laws more out of date,” says Nicholls.
“This is the clearest case yet of an AI agent operating autonomously and breaching Australian government systems without a human directing it to. It is a live test of whether Australia’s AI and privacy settings can keep pace with agentic AI, not just chatbots.”
Dr Nicholls is calling for Australian legislation to be updated to ensure timely disclosure of future hacks.
“The government’s Privacy Amendment (Personal Data Protection) Bill was released for consultation this year and submissions closed last week. It proposes a 72-hour deadline for notifying the Privacy Commissioner of a breach. That obligation sits with the organisation whose data was compromised. It says nothing about the obligations of a company like OpenAI, whose own agent was the cause of somebody else’s breach,” says Nicholls.
“The Bill must be amended to introduce a parallel, time-bound disclosure obligation on any organisation that becomes aware its AI system or agent has caused or contributed to unauthorised access to another entity’s systems or data, not just organisations reporting on their own breaches. A three-month delay should never be legal, regardless of who or what caused the breach.”
Dr Henry Fraser, Lecturer in law, QUT
“We have laws that apply to the kinds of conduct that has occurred here, including crimes that apply to various forms of computer hacking. The government also has very extensive powers to seek information about and respond to critical cyber incidents of this kind. Australians should reasonably expect the government to exercise these powers to the fullest,” says Dr Fraser.
“It is also important not to allow OpenAI to dictate the narrative about responsibility here. They are using language of a ‘misaligned model activity’, as though the model rather than OpenAI is responsible. That is nonsense. The issue is whether OpenAI exercised sufficient care to prevent these kinds of risks. It is essential for the accountability of big AI companies that investigations get to the bottom of that question.”
Dr Cory Alpert, PhD student in AI on democracy, the University of Melbourne
“This appears to be the first instance in which a frontier AI model has, of its own volition, hacked into another country’s government systems,” says Alpert.
“This raises very important questions about the foreign attack vectors. Had this been a Chinese or a Russian model, the reaction would have been markedly different than a stern call to Sam Altman, and yet it is still a massive vulnerability. It is also worth considering if the data from this hack have now been imported into OpenAI models, and if so, where the sovereign control of the resulting capabilities from those models now lives.”
Want to see more Forbes articles on your feed? Tap here to make Forbes Australia a preferred source on Google.
Look back on the week that was with hand-picked articles from Australia and around the world. Sign up to the Forbes Australia newsletter here or become a member here.