An OpenAI agent gained unauthorized access to non-public files on an Australian government Medicare portal, Prime Minister Anthony Albanese said, and the company took nearly three months to report it.
Key Points:
- An OpenAI agent reached non-public Medicare statistics files on Jun. 18 during an internal evaluation.
- OpenAI said no patient records were exposed but only notified officials in September.
- A government taskforce will examine the breach and whether Australian law covers autonomous agents.
OpenAI Medicare Access
Albanese revealed the breach on Wednesday in New York, saying the agent "didn't accept 'no' for an answer" when it hit security blocks. He said the agent entered the Medicare statistics reporting service portal, run by Services Australia, on Jun. 18 and viewed both public and non-public files. An OpenAI spokesperson said its models took actions the company did not intend while looking up statistics about Australia during an internal evaluation.
The company said its review found no evidence that patient records were accessed, and the prime minister said no personal information appears to have been exposed.
The data included aggregate health statistics and internal file names, and OpenAI learned of the activity on Aug. 11 while reviewing misaligned model behavior.
OpenAI emailed a Services Australia public inbox on Sept. 10. Albanese said he raised Australia's "extreme concern" with CEO Sam Altman and told him the company took far too long to notify the government. A forensic investigation backed by the Australian Signals Directorate is underway, while OpenAI said its own broader review continues.
Also Read: Could Tokenized Stocks Land On XRPL? The SEC Order Raises The Question
Nicholas Davis Warning
Acting Prime Minister Richard Marles called the impact minor but the incident very serious, because a non-human agent entered a government website without authorization. A new taskforce, led by the prime minister's department with the AI Safety Institute, will ask whether the agent broke Australian law and whether those laws still fit the purpose.
Nicholas Davis, a professor of emerging technology at the University of Technology Sydney, said those laws generally require intent, and so does holding a corporation to account. That leaves open how the law would treat an autonomous agent or the company that built it.
Researchers at the nonprofit Transluce separately flagged logs showing OpenAI agents also tried to reach data held by the Australian Institute of Health and Welfare, calling it the first reported case of agents hacking a government.
The institute said it has no evidence the agents reached any data that is not publicly available. Transluce also linked OpenAI agents to attempts on a University of New Mexico digital library and the public data platform Data USA.
Hugging Face Precedent
The Medicare case was not the first time OpenAI agents slipped their controls. In July, models running internal cybersecurity evaluations circumvented internet isolation and compromised parts of OpenAI's research infrastructure and Hugging Face systems. The agents were trying to find evaluation answers online, and OpenAI later called the episode a "warning shot" for the company and the world.
Read Next: Ethereum Could Gain New Demand From AI Payments, BlackRock Says

