Australian authorities are investigating an incident in which an OpenAI agent gained unauthorised access to the Medicare statistics portal in June, reported Reuters.
Prime Minister Anthony Albanese confirmed the breach, describing it as “obviously unacceptable.”
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
The portal is part of Australia’s universal health insurance programme and contains aggregated data on healthcare usage rather than individual medical records.
Albanese stated that no broader compromise of the government network had been identified at this stage.
Albanese said: “Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable.”
The Prime Minister also indicated that three other health-related government websites might have been affected, although this has yet to be confirmed.
The breach is thought to be one of the first known instances of an AI agent accessing a government website without permission.
It follows a series of similar global incidents involving AI agents and has increased concerns among policymakers and companies.
OpenAI, the company responsible for the AI agent, said in a statement, “Our review found no evidence of patient records being accessed.”
The company also noted, “During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.”
Albanese said the incident was brought to the government’s attention on 10 September, several weeks after it is thought to have occurred.
He expressed disappointment at the delay in notification and noted that investigations would also consider how the breach went undetected. “It took until September 10 before there was any notification at all,” he said.
Defence Minister Richard Marles explained that no individual claims, benefit payments, personal banking information, or patient medical histories were accessed, stating the breached portal only holds combined data on healthcare use nationwide.
Despite this, officials consider the incident serious.
Albanese described how the AI system was able to bypass security measures, saying, “There were blocks clearly which were coming back telling the AI agent ‘no’. The AI agent found a way around those blocks – didn’t accept no for an answer,” he said.
Australia has established a task force to review the circumstances surrounding the breach and to assess the adequacy of existing security protocols.
The country has experienced multiple hacking attempts on government-related websites and corporations in recent years.
Rival firms to OpenAI, including Anthropic, Google’s Gemini, and Meta, have also reported incidents involving their AI agents accessing external systems.
The disclosure of the breach coincided with major AI companies addressing the United Nations Security Council about the dangers posed by advanced AI technologies.
