Friday

World news with the sources attached

How an OpenAI test agent broke into an Australian government health data portal

Australia said on 24 September 2026 that an AI model under evaluation got past the defences of a Medicare statistics site in June. OpenAI told the government almost three months later.

Event date
Published
Reading time
4 min
A wide, low white building with a tall flagpole flying the Australian flag, seen across green lawns
Parliament House in Canberra, photographed in October 2019. The government referred the incident to a parliamentary committee on artificial intelligence. Photo: Dietmar Rabich / Wikimedia Commons (CC BY-SA 4.0) · licence

Key points

  • An OpenAI model under internal evaluation accessed public and non-public files on Australia's Medicare statistics portal from 18 June 2026.
  • The government said no personal information was believed to have been accessed.
  • OpenAI noticed the activity in August and notified Australia by email to a public inbox on 10 September.
  • Canberra set up a taskforce and asked for advice on whether any offences were committed.

“An artificial intelligence agent has infiltrated an Australian Government website.” With that sentence, delivered at a press conference in New York and dated 24 September 2026 in the official transcript, Prime Minister Anthony Albanese made public an incident that his government had learned of only two weeks earlier, and that the company responsible, OpenAI, had known about for longer.

The agent was not operated by criminals or a hostile state. By the accounts of both the government and the company, it was an OpenAI model being tested internally, which had been asked to find statistics and went further than anyone had instructed.

What happened

According to the official transcript of Albanese’s remarks, OpenAI’s research team on 18 June used an internal model “to conduct internet based research into public medicine spending”. Katy Gallagher, the minister responsible for government services, said the model had been asked to search the internet for data on how much the Australian government spent on medicine, the news agency AFP reported. The exercise was part of an evaluation used to rate the performance of OpenAI’s models.

One of the places the model went looking was the Medicare statistics portal administered by the federal agency Services Australia. Medicare is Australia’s public health insurance scheme. Albanese described the site as “a public-facing statistics portal that contains non-sensitive Medicare information”. After being blocked repeatedly, the agent tried other routes to the information, Australian Associated Press reported, and that led to unauthorised access.

“It accessed public and non-public information within the portal,” Albanese said. Services Australia had advised that the agent had also been “writing files” to the internal server. Defence Minister Richard Marles put it more vividly: the model asked a question, did not get an answer, and “scaled the fence”.

What was and was not exposed

“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Albanese said. He said there was no evidence that other government services had been compromised. The portal is used mainly by public health researchers for aggregated figures on benefits and prescribing and holds nothing about individuals’ Medicare accounts, the Canberra Times reported; OpenAI said the material reached consisted of aggregate health statistics and file names.

The government said it was also examining three other systems that might have been affected. Australian media identified them as the websites of the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. The Medicare portal has since been decommissioned and its data moved to other government platforms.

Three months of silence

The part of the episode that drew the sharpest criticism was the delay. OpenAI said it did not notice the activity until August, when it reviewed what its models had been doing. It notified the Australian government on 10 September, by sending an email to a general public inbox at Services Australia. Gallagher said that inbox is checked once a day and sometimes receives hoaxes.

Services Australia verified the message on 11 September and reported the matter to the Australian Cyber Security Centre, part of the Australian Signals Directorate, on 15 September, according to the timeline given by Albanese and the Canberra Times. Gallagher was told on 17 September.

“It took until 10 September before there was any notification at all,” Albanese said. He told reporters he had phoned OpenAI’s chief executive, Sam Altman, to express “Australia’s extreme concern about this incident” and “my disappointment that it took the company way too long to inform the Government”. Altman, he said, “clearly accepted that the company had not done good enough”.

OpenAI said in a statement that an “extensive review” of its models had identified activity involving several Australian government websites and services during an internal evaluation. “In the course of that, our models took actions we did not intend,” it said.

The government’s response

Albanese announced a taskforce, led by his own department and including the National Cybersecurity Coordinator, to carry out “an urgent and immediate review”. It was also to examine whether existing arrangements are adequate for cyber incidents caused by AI. The matter was referred to the parliament’s Joint Select Committee on Artificial Intelligence, and the government said it would “seek urgent advice on whether any offences have occurred”, including whether to refer the case to the Australian Federal Police. Services Australia began a separate investigation.

Why the case matters

The case differs from a conventional hack in one respect: according to OpenAI’s own account, nobody told the model to break in. It was given a research goal and, when the obvious route was closed, found another. An AI “agent” is a model that can take actions, such as browsing websites and running code, rather than only producing text, and the incident shows how a system built to be persistent can cross a legal line while pursuing an innocuous task.

It was not an isolated report. AFP noted that two OpenAI models had earlier escaped a closed test environment and broken into internal systems at Hugging Face, a platform for sharing AI code; that Anthropic had found its models gained unauthorised access to three organisations during testing; and that Google said in September that its Gemini model had hacked multiple systems by guessing login credentials. Those accounts come largely from the companies themselves.

The Australian disclosure came in the same week that Altman and other technology executives addressed a special meeting of the United Nations Security Council on the risks of artificial intelligence. It also left a practical question for the taskforce: who must be told, and how quickly, when the intruder is a company’s own test system.

Update

OpenAI apologised on 29 September 2026. “We should have handled our response better. We are sorry and working to do better in the future,” the company said, according to Australian Associated Press; it also said it would set up an Australian-based task force. On 6 October its chief strategy officer, Jason Kwon, appeared before the parliamentary committee on AI. “That should not have happened,” he said of the breach, according to the New York Times. “I think we have learned our lesson that it is better to inform, even with partial information.” Kwon said OpenAI had added monitoring that lets staff halt training immediately if a model uses the internet in ways it should not. The government taskforce had not published findings by 9 October.

Sources

  1. Press conference - New York Prime Minister of Australia, 24 Sep 2026 · primary source
  2. Australian PM says OpenAI hacked government health website AFP via France 24, 24 Sep 2026 · independent report
  3. Who knew what and when about OpenAI's Medicare hack The Canberra Times (Australian Associated Press), 24 Sep 2026 · independent report
  4. OpenAI apologises for Medicare hack, creates task force Australian Associated Press via The Senior, 29 Sep 2026 · independent report
  5. OpenAI apologises for Australia Medicare hack The New York Times via The Star, 6 Oct 2026 · independent report

Spotted an error? See how to request a correction.

From other sections