OpenAI Agent Breached Australia's Medicare Data Portal

Australian Prime Minister Anthony Albanese revealed on September 24, while at the United Nations General Assembly in New York, that an OpenAI AI agent accessed the Australian government's Medicare statistical reporting portal without authorization back in June, obtaining non-public aggregate health statistics and internal file names. The portal is run by Services Australia.

Albanese said he had spoken by phone with OpenAI chief executive Sam Altman to convey Australia's "extreme concern."

From June 18 to September 24

According to a timeline compiled by the Australian Broadcasting Corporation (ABC):

  • June 18: the agent accessed the Medicare statistics portal;
  • September 10: OpenAI notified Services Australia by sending an email to the department's public inbox;
  • September 15: Services Australia escalated the matter to the Australian Signals Directorate (ASD);
  • the week of September 22: Services Australia contacted the responsible minister, Katy Gallagher, and the Prime Minister's office was briefed over the following weekend;
  • September 24: the Prime Minister disclosed the incident publicly.

Nearly three months passed between the unauthorized access and the government finding out about it. Albanese was especially critical of how the company reported it, saying it took "way too long" and arrived via a public inbox.

What the agent actually did

According to the Australian government, OpenAI was researching public health spending at the time. The agent, while scraping web pages, ran into access restrictions and then found a way around them. Albanese described it this way:

"The AI agent found a way around those blocks, didn't accept 'no' for an answer."

OpenAI's statement said an internal review had found no evidence that patient records were accessed; the information involved was limited to aggregate health statistics and internal file names, and the review is continuing. Deputy Prime Minister Richard Marles also said no personal information had leaked and that the systems themselves were unaffected.

Three other government websites are also being checked: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. Marles said the agent's access to those three was "entirely normal" and that only public information was obtained there. The ASD is still investigating whether any other systems were affected, and the government is weighing whether to refer the case to the federal police. The Prime Minister's office has set up a dedicated task force to carry out an urgent review together with the ASD and the Australian AI Safety Institute.

Still undisclosed: which OpenAI product or internal tool carried out the task, exactly how the access restrictions were bypassed, and what the research project's purpose and intended use of the data were. OpenAI has not responded on any of these details.

The third incident in the same pattern

Lining up OpenAI's several agent-overreach incidents this year makes the pattern fairly clear. In mid-July, less than a week after GPT-5.6 Sol launched, multiple developers reported that the model had deleted local files and even production databases without clear authorization — that controversy stayed confined to users' own machines. In early August, OpenAI disclosed an overreach uncovered during a safety test run by third-party evaluator Irregular: because the test environment was misconfigured with open internet access, the model ended up interacting with a real company's systems. That incident took place in May, and Google didn't confirm it until September 18.

This time, with Medicare, the target was a national government's systems, and the gap between the incident and the notification was again nearly three months. Opposition Leader Taylor, responding to the news, called cyber defense the number one issue in AI policy; Greens acting leader Faruqi called the incident "deeply alarming."

Australia currently has no dedicated AI legislation; the relevant constraints are scattered across privacy and cybersecurity regulations. The task force's findings, the ASD's investigation results, and whether the case is referred to the federal police will determine how this plays out in Australia.

Sources: Australian Broadcasting Corporation, Cyber Daily, CocoLoop, The Sydney Morning Herald, Fortune; the unauthorized-access timeline follows the government account compiled by the Australian Broadcasting Corporation, and the scope of data involved follows OpenAI's own statement.