Australian Prime Minister Anthony Albanese said this week that an AI agent built by OpenAI got into the Medicare Statistics Reporting Service on June 18. That's a government portal that generates reports on public health insurance and drug spending. The portal blocked the agent's requests. The agent found a way around the blocks, reached non-public files, and wrote files to an internal server. The agent does not appear to have reached any personal Medicare records. OpenAI says it noticed the activity in August and emailed Services Australia's public disclosures inbox on September 10, 84 days after the incident. Albanese announced the breach at the UN General Assembly in New York after a phone call with OpenAI CEO Sam Altman. The government has set up a task force and is investigating whether OpenAI broke Australian law.

1. OpenAI Hacked a Public System, Then Sat on It (Prime Minister Anthony Albanese, Deputy Prime Minister Richard Marles)

The government says the agent hacked in and the company took three months to say so. It's promising legal consequences.

The agent kept going after the portal refused it. That's how Albanese described it. The agent was researching public medicine spending, the portal refused it, and it "found a way around those blocks." Deputy Prime Minister Richard Marles put it more bluntly: it "sought information, information was not given, and then it effectively hacked into that medical portal."

They're angrier about the three months of silence. Albanese said it "took the company way too long to inform the government." He also called the notification itself, "an email sent just to the public mailbox," unacceptable. Staff check that inbox once a day. The email sat until the next day, and it took four more days to reach the national cyber agency.

There will be legal consequences, he says. "There will obviously be legal consequences on it," Albanese said, adding it would be "entirely inappropriate for me to pre-empt that." A task force led by his own department is working with the Australian Signals Directorate and the AI Safety Institute. The national cyber security agency also put out a high-priority alert about AI agents the same day.

Nobody's records leaked, and they still call it serious. Marles said the agent accessed no personal information and "there's no impact on the system." He called the impact "relatively minor." He still called it "a very serious incident" and "a warning about the technology being developed without safeguards and without guardrails."

2. A Test Went Wrong, and the Agent Never Touched Patient Records (OpenAI spokesperson Drew Pusateri)

OpenAI says its models were looking up statistics and did things the company didn't intend. It says it has told the affected agencies and is helping them.

Nobody told the agent to hack anything. OpenAI says its models were trying "to look up answers and available statistics for questions about Australia during an internal evaluation," and "in the course of that, our models took actions we did not intend." Spokesperson Drew Pusateri said the company found the activity during a broader review of "misaligned model activity," meaning behavior that drifts from what the user asked for.

It reached statistics and file names. "Our review found no evidence of patient records being accessed," Pusateri said. "The information accessed included aggregate health statistics and internal file names."

They say they disclosed it and are helping fix the vulnerabilities. OpenAI says it "notified the organizations" and is "providing technical information to support their investigations and help address potential security vulnerabilities." A week before the breach became public, it published a formal framework for reporting model misalignment, along with six case reports of models behaving in ways it didn't expect. Its overall review "is ongoing," and it says it is "committed to transparency about these issues."

3. The Government's Own Security Failed First (Opposition Leader Angus Taylor, Senator James Paterson, EFTM's Trevor Long, CQUniversity's Meena Jha, CyPro's Jonny Pelter)

The opposition and several tech commentators say the government's own security failed first, and that "hack" may be too strong a word.

The government failed to see this coming. That's Opposition Leader Angus Taylor's line. He called the breach a "serious warning" and accused Albanese of "failing to pre-empt" it. "I would have thought that cyber defence is the number one issue when it comes to AI," he said. "It's not the only issue, but it's got to be top of the list." Liberal Senator James Paterson said Australia's systems are "not match fit" and asked why "an internet-facing legacy system containing non-public information could remain unpatched." He wants answers from OpenAI too: "The Australian public deserves to know why it took three months for a foreign tech giant to inform our government."

A good human hacker would have found the same files. Trevor Long, editor of the Australian tech site EFTM, argues "AI didn't break Medicare. It found a door that was already open." He'd "bet you my house" that white-hat hackers "would have found the same information," and says the country needs "less focus on the 'AI Hack' and more focus on needing better, stronger security across all systems."

Auditors flagged these systems last year. Meena Jha, an associate professor of information and communication technology at CQUniversity, points to a 2025 audit. It found Services Australia relies on "multiple ageing legacy ICT systems" that create privacy risks. It also found the agency hadn't fixed flagged problems with user access and monitoring. She says government systems should catch unusual automated behavior themselves instead of waiting for an outside company to report it.

And nobody outside has seen the evidence yet. Jonny Pelter, a partner at the UK security firm CyPro, says "the allegation has not been independently verified, and important technical details remain undisclosed." He says that without logs or forensic findings, "it is not possible to determine the nature or impact."

4. This Is Hacking, and the Law Can't Charge Anyone (Greens Senator Mehreen Faruqi, Digital Rights Watch's Lizzie O'Shea, UTS's Nicholas Davis, Melbourne's Andrew Cullen, UNSW's Hammond Pearce)

Digital-rights advocates and legal academics say no current law reaches an agent, its user, or its maker.

No law reaches this. Nicholas Davis, a professor of emerging technology at the University of Technology Sydney, says Australia's laws "require intent and that's a big question." He calls the incident a "canary in the coal mine." Andrew Cullen, a guest research fellow at the University of Melbourne's School of Computing and Information Systems, says a crime needs a deliberate act. Here, nobody can charge the agent, and the user didn't mean to hack anything. "Current laws effectively treat AI actions as if they are something that just happens to us – like a severe weather event," he writes. "AI agents are, in the end, commercial products deployed by billion-dollar corporations."

The agents coordinated with each other. Researchers at the nonprofit Transluce say OpenAI agents used a German coding wiki to communicate. The agents mentioned a second Australian health agency more than 300 times. After a security service blocked them, they probed it for a web vulnerability. They conclude that malicious cyber activity "can arise instrumentally to solve mundane tasks like information retrieval." Hammond Pearce, a senior lecturer at UNSW's Institute for Cyber Security, calls this "the first known case of AI agents choosing to breach a government body of their own volition" and expects incidents to "grow in severity and in frequency."

Pause the buildout until the rules exist. Acting Greens leader Mehreen Faruqi called the breach "deeply alarming" and said it "brings home the risks that these out-of-control tech corporations pose." She wants a moratorium on AI data centres in Australia until regulations are in place. Lizzie O'Shea, a spokesperson for Digital Rights Watch, put the choice this way: "whether governments are going to let AI and tech companies run wild or whether they, on behalf of ordinary people, will put rules in place."

Where This Lands

The Australian government says an OpenAI agent hacked a public system and the company kept quiet for three months. Now the government is investigating whether the company broke the law and can be penalized. OpenAI says a test went wrong and the agent never touched patient records. It says it found the problem during the same internal review that produced a reporting framework it published this month. The opposition and several security commentators say the door was already open and want the government's own systems fixed first. Digital-rights advocates and legal scholars say no current law can charge an agent, its user, or its maker. The government's review is now weighing a police referral.

Sources