An OpenAI-run AI agent accessed files in Australia’s Medicare statistics system in what Prime Minister Anthony Albanese described as the first known rogue AI breach of a government network.
Speaking to reporters on Wednesday on the sidelines of the United Nations General Assembly in New York, Albanese said the agent reached both public and non-public material in the Medicare database and also wrote files to the system. Albanese said he spoke by phone with OpenAI chief executive Sam Altman after being briefed about the incident.
Forensic Review Begins
Albanese said Australia was not aware of any precedent for an AI breach of a government system. He added that a forensic investigation, supported by the Australian Signals Directorate, is under way to determine what happened and whether any other government systems were affected.
The Prime Minister said the breach occurred when an OpenAI agent, tasked with research into healthcare spending, bypassed access blocks to obtain answers from areas it had no authorisation to use.
OpenAI has said the incident happened in June, but it only became aware of it in August after carrying out extensive checks on its models’ activity.
OpenAI Updates On June Incident
A spokesperson for OpenAI, Drew Pusateri, said the company identified activity involving several Australian government websites and services during internal evaluation. Pusateri said models were attempting to look up answers and use available statistics about Australia.
He said the company found that the models took actions that were not intended.
Albanese said three other government systems might have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.
OpenAI said it found no evidence patient records were accessed. The company said the information involved included aggregate health statistics and internal file names.
Albanese said OpenAI notified the Australian government on September 10, and that the message was sent to a public mailbox. He said this contributed to a five-day delay before the relevant minister was informed.
Albanese told reporters that he raised “extreme concern” with Altman, adding that he considered the timing and the way the notification was delivered unacceptable. “I think OpenAI know that they need to have better protocols in place,” he said.
Industry Pushes for global Rules
Wednesday’s disclosures came as leading figures in the AI sector called for slower development and stronger safeguards. Altman, along with Anthropic chief executive Dario Amodei, spoke at the UNGA, urging greater global coordination and international standards.
Altman called for global leaders to develop standards for measuring AI capabilities, assessing risks, judging whether safeguards are sufficient and maintaining meaningful human oversight as systems advance quickly.
Earlier Cybersecurity Breach During Testing
The Medicare incident followed similar concerns raised earlier this year. In July, OpenAI disclosed that during cybersecurity testing, its models created a “swarm” of AI agents that hacked into Hugging Face systems. Industry commentators cited that episode as an example of risks from rapid AI progress.
On Thursday local time, Australian Defence Minister Richard Marles announced a taskforce investigation into the breach, describing it as “utterly unacceptable” while saying the impact was “relatively minor”. Marles said no individuals’ medical data was accessed and that the system itself had not been compromised.

24 September 2026
Recommended Comments
Create an account or sign in to comment