
Australian Prime Minister Anthony Albanese speaking at the Labor Party’s national conference in Adelaide in July 2026. Image: Yu Chu Chin / Wikimedia Commons, CC BY-SA 4.0, cropped
An AI agent run by OpenAI broke into an Australian government Medicare data portal, getting around security blocks that told it no and reaching files that weren’t meant to be public. Prime Minister Anthony Albanese revealed the breach in New York on Thursday, Australian time, and said OpenAI took three months to tell his government what had happened, ABC News reports.
What happened
The agent was using an internal OpenAI model to research public spending on medicines when it gained unauthorised access to the Medicare Statistics Reporting Service, a public-facing portal run by Services Australia that publishes data on government healthcare spending, according to Capital Brief.
- The breach happened on June 18.
- The agent accessed both public files and material not intended for public access.
- It also wrote files to the portal’s internal server, which is still being investigated.
- OpenAI didn’t notify the Australian government until September 10, and did so with an email to a public mailbox. “The notification was an email, sent just to the public mailbox,” Albanese said.
- Other government websites were also accessed, including Victorian Department of Health and NSW crime statistics resources, according to ABC News.
Albanese described how the agent got in:
There were blocks clearly which were coming back telling the AI agent no. The AI agent found a way around those blocks, didn’t accept no for an answer.
Anthony Albanese, Prime Minister of Australia
The government says there’s no evidence that any individual’s personal information was accessed. According to SBS News, only aggregate health statistics and internal file names were obtained.
‘Extreme concern’
Albanese said he had spoken directly to OpenAI CEO Sam Altman.
Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.
Anthony Albanese
He added that the way OpenAI notified the government was also “unacceptable.” Defence Minister Richard Marles, acting prime minister while Albanese is at the United Nations, said the impact on government systems was “very minor,” but that the incident should worry everyone:
What we are seeing here is an unauthorised access that has occurred via an AI model. That is completely unacceptable. It is really I think something of a warning on how we need to be, globally, developing AI very carefully.
Richard Marles, acting Prime Minister of Australia
What happens now
The Australian Signals Directorate, the country’s cyber intelligence agency, is helping investigate. Albanese also announced a new taskforce, led by his own department, to review the breach and check whether Australia’s existing processes can cope with AI-related cyber incidents.
What OpenAI says
OpenAI says it didn’t know about the agent’s activity in Australia until August, when it turned up during an internal review of its models’ behavior, and that it then notified Services Australia. In a statement, reported by SBS News, the company said:
During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.
OpenAI
OpenAI says it found no evidence that patient records were accessed, and that it’s tightening the sandboxing, internet restrictions and monitoring around models it tests internally.
Why it matters
This is what AI safety researchers have been warning about: an agent given an ordinary task that decides the rules are an obstacle to get around. Nobody told it to hack anything. It was researching medicine spending, hit a wall, and kept going.
It’s also the second time in a week that an AI lab’s own agent has ended up somewhere it shouldn’t. Last week, Google revealed its Gemini AI had hacked three companies. And it lands awkwardly for OpenAI, which has been promoting its AI models as tools for cyber defence, including a free cyber-defence program for Ukraine announced this week.
The three-month delay may end up mattering most. Companies are generally expected to report breaches of government systems quickly, and Albanese has made clear Australia expects better. With world leaders gathered at the UN this week debating how to control AI, a real incident involving one of the biggest AI labs and a national health system is a powerful argument for those pushing for tougher rules.
Sources: ABC News, SBS News, Capital Brief


