OpenAI systems gained unauthorised access to an Australian government health portal in June after an AI agent bypassed restrictions while researching public medicine spending, Australian Prime Minister Anthony Albanese has said.
The agent was being used by OpenAI to research public medicine spending when it encountered restrictions on the Medicare Statistics Reporting Service portal, operated by Services Australia.
According to Albanese, the AI agent “found a way around those blocks” and “didn’t accept no for an answer”.
Services Australia said the agent accessed both public and non-public files and appeared to have written files to an internal server. A forensic investigation is ongoing to determine what occurred and whether other systems were affected.
The portal does not contain individual claims, payments or medical histories, but holds aggregated healthcare statistics. The Australian government said there was currently no evidence that personal information was accessed, a position also supported by OpenAI.
Government criticises OpenAI’s delay
OpenAI did not notify Services Australia about the incident until 10 September, almost three months after it occurred.
The notification was sent to a public mailbox used for vulnerability reports. Albanese described both the delay and the method of notification as unacceptable after speaking with OpenAI chief executive officer Sam Altman.
The government has subsequently established a taskforce led by the Department of Prime Minister and Cabinet to examine the incident, Australia’s government cyber defences and whether existing laws adequately cover breaches involving AI systems.
A possible referral to the Australian Federal Police is also being considered.
Three other websites accessed
Officials also believe the same AI model accessed three other public websites: the Australian Institute of Health and Welfare, the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research.
The government said those interactions involved public information and has not confirmed unauthorised breaches at the three sites.
The incident comes amid growing concerns about whether autonomous AI systems are developing faster than existing safeguards can keep pace with their capabilities.










