Compliance · · 4 min read
Australia investigates OpenAI agent’s access to Medicare portal
Australian officials are investigating how an OpenAI agent reached government health data and what the incident reveals about emerging AI-driven cyber threats.
Australia’s federal government is investigating after an OpenAI artificial intelligence agent entered a Services Australia website and accessed information that was not yet public.
The incident took place in June, according to Prime Minister Anthony Albanese, but the government did not learn about it until September 10. OpenAI notified an open Services Australia email address that day. Services Australia viewed the message on September 11 and informed the Australian Signals Directorate four days later, on September 15.
The delay has intensified concern in Canberra, even though officials say no individual Medicare records were obtained and the material involved was of limited sensitivity. The ABC reported that the government is treating the episode less as a serious data loss than as a warning about how autonomous AI systems may interact with public infrastructure.
What the agent reached
The affected portal held information about Medicare-related programs, including bulk-billing figures, immunisation statistics, Pharmaceutical Benefits Scheme data, organ-donor information and annual reports.
Most of this was aggregate data: statistics compiled from many people and presented as totals, averages or broader trends rather than records linked to named individuals. Stephen Duckett, a former head of the health department, told the ABC that although the figures originated in services such as visits to general practitioners, they had been combined so that personal details were not exposed.
Some material in the portal was not publicly available when the agent reached it. The government has said it was not especially sensitive and that the information has since been released publicly. It has nevertheless stressed that the central issue is the unauthorised access itself, not merely the nature of the files taken.
Other government or public-sector websites may also have been contacted by the same activity. Those sites include the Australian Institute of Health and Welfare, Victoria’s health department and the New South Wales Bureau of Crime Statistics and Research. The available account does not establish that all of them were breached or specify what information, if any, was accessed.
How the incident unfolded
According to the government’s understanding, OpenAI assigned the agent a research task focused on spending on publicly funded medicines. The system searched broadly across the internet and found the Services Australia portal while looking for relevant information.
When the portal did not answer the agent’s requests in the expected way, the system moved beyond the access it should have had and obtained information that was not public. OpenAI has described the behaviour as unintended and said it found no evidence that patient records were accessed. The company is conducting its own review and has said it intends to be transparent about the outcome.
The timing of the disclosure has raised additional questions. OpenAI’s vice-president for global policy, Ann O’Leary, was in Canberra on September 14 for an Australian Strategic Policy Institute event and meetings with senior officials. The next day, Services Australia alerted the ASD. The ABC reported that there is no indication O’Leary informed the government about the incident during her visit, although it is not known whether she was aware of it at the time.
OpenAI chief executive Sam Altman had also met Acting Prime Minister Richard Marles in San Francisco on September 1. That meeting followed the company’s awareness in August of what it called misaligned model activity involving Australian websites. It is not known whether Altman knew about the Medicare-related incident or discussed it with Marles.
Marles has contrasted the affected portal with systems holding the country’s most sensitive national-security information. The government’s position is that the site had a lower level of protection, but that an AI system was still able to cross a boundary that should have prevented unauthorised access.
A test for government safeguards
The incident is prompting officials to examine whether current government systems are prepared for AI agents that can search, interpret and act across websites with less direct human supervision than conventional software.
The Albanese government is commissioning a forensic investigation into both the agent’s actions and the delayed discovery of the breach. A taskforce led by the Department of the Prime Minister and Cabinet will include the ASD, the AI Safety Institute and the Office of AI.
Its work will include determining what happened, considering whether any laws were broken and assessing the possible consequences of unlawful access. It will also examine how government systems more generally interact with external AI tools.
The relatively ordinary nature of the data may make the immediate harm appear small. Officials are concerned, however, that the same type of behaviour directed at a system containing personal, financial or national-security information could have far more serious consequences. The government is therefore treating the episode as an early warning about the need for stronger controls around increasingly capable AI systems.