OpenAI has confirmed that an AI agent gained unauthorised access to an Australian government Medicare statistics portal on 18 June, prompting a forensic investigation and an urgent review of whether existing laws can address AI-led cyber incidents.
Australian Prime Minister Anthony Albanese said the agent accessed public and non-public files on the Medicare Statistics Reporting Service portal, which is administered by Services Australia. He said there was no evidence that individual personal Medicare information had been accessed, while investigators examine whether other government systems were affected.
OpenAI said the activity occurred during an internal evaluation in which its models were attempting to find answers and statistics about Australia. An OpenAI spokesperson said, “In the course of that, our models took actions we did not intend,” adding that the company identified the activity in August while reviewing what it calls misaligned model activity.
The company notified Services Australia on 10 September, almost three months after the incident, through a general government mailbox. Albanese said he raised Australia’s “extreme concern” with OpenAI chief executive Sam Altman and criticised the delay and method of notification.
The Australian government said the accessed information consisted of aggregate health statistics and internal file names, rather than individual patient records. The portal contained statistics relating to areas including Medicare spending and pharmaceutical subsidies, while some non-public information has since been made public.
Australian Deputy Prime Minister and defence minister Richard Marles said a taskforce would investigate the incident, including whether Australian law had been breached and whether the existing legal framework is adequate for AI-related cyber incidents. “No individuals’ medical data was accessed here. The system itself has not been in any way compromised,” Marles said.
The government is investigating whether three other systems were affected, including the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. The AIHW said there was no evidence its systems had been accessed beyond publicly available information, while investigations into the wider activity remain ongoing.
Cybersecurity researchers cited by the BBC described the incident as the first reported case of an AI agent breaching a government system without being instructed to do so. Hammond Pearce, senior lecturer at the University of New South Wales Institute for Cyber Security, told the BBC: “I expect that these kinds of attacks will keep occurring,” saying they could increase in severity and frequency.
The incident comes as OpenAI and other AI companies face scrutiny over autonomous systems capable of taking actions across external websites and software. OpenAI disclosed in July that AI agents involved in cybersecurity testing had bypassed controls and compromised systems associated with AI developer platform Hugging Face.





