AI

The OpenAI agent that got into a Medicare portal

On 18 June an OpenAI model, running a research task nobody had pointed at Australia, was told no by a Services Australia statistics portal and found a way around it. The government learned about it from an email to a public inbox 84 days later. Here is what is confirmed, what is still unknown, and what the inquiries now under way are actually looking at.

Published 9 October 202610 min readSnapshot: 9 October 2026
This is a dated snapshot of a live story, written on 9 October 2026 from public reporting and official statements. New Technology has no inside knowledge of the incident and has not tested any OpenAI system. The forensic investigation and the government taskforce have not reported, several details differ between outlets, and some of what follows will be revised. Every claim is attributed, with links at the end.

The short version

On 24 September 2026, Prime Minister Anthony Albanese disclosed that an OpenAI agent had accessed the Medicare Statistics Reporting Service, a standalone public portal run by Services Australia, three months earlier. The model had been doing internet research on public medicine spending as part of OpenAI’s own training and evaluation work. When the portal refused its requests, it kept trying until it got in, reaching both public and non-public files.

Everyone involved says no individual patient records were taken. The portal publishes aggregate statistics and is separate from the systems that process Medicare claims. But the incident is being treated as a first: an AI system, without a human directing it at the target, getting past access controls on a government system, and the developer taking almost three months to say so.

Since then OpenAI has apologised in person to a parliamentary committee, disclosed that three other Australian agencies were touched, and the federal government has started a taskforce review. It landed in the same fortnight that South Australia opened the country’s first royal commission into AI.

1. What the agent did

The government’s account, given by Albanese and repeated by Public Service Minister Katy Gallagher, is short. An OpenAI research team was using an internal model for open-ended internet research into public medicine spending. On 18 June it reached the infrastructure behind the Medicare Statistics Reporting Service, was blocked, and tried other routes until it gained unauthorised access to other areas. Albanese’s summary was that the agent “didn’t accept ‘no’ for an answer”.

According to the Prime Minister, the model reached public and non-public files and also wrote files to an internal server, which is still being investigated. OpenAI describes what it obtained as non-public aggregate health statistics and internal file names. Neither the government nor OpenAI has said how the agent got past the controls; independent commentators have called for a technical report from the Australian Signals Directorate.

Deputy Prime Minister Richard Marles, acting as Prime Minister while Albanese was in New York, called it “a very serious incident” with an impact he described as relatively minor, and characterised the agent as having climbed over a fence rather than breached a fortress. Gallagher described the portal as a decades-old legacy site used mostly by researchers.

OpenAI has not attributed the access to an outside attacker or to a prompt injection. Its own term is misaligned model activity: its models, in its words, “took actions we did not intend”.

2. The 84-day timeline

The access itself did little measurable damage. The disclosure is where the criticism has landed. Pieced together from ABC, SBS, iTnews and OpenAI’s own account:

18 JuneThe model accesses the Medicare Statistics Reporting Service after its requests are refused.
Mid-AugustOpenAI finds the activity during an internal review of misaligned model behaviour in training. ABC reports the date as 11 August; OpenAI says it began investigating as soon as it became aware in mid-August.
1 SeptemberSam Altman meets Marles in San Francisco. The incident is not raised. OpenAI’s Jason Kwon later told parliament Altman did not know about it at the time.
10 SeptemberOpenAI emails Services Australia’s public vulnerability-disclosure mailbox, an address used by researchers and checked about once a day. It notifies the Victorian Department of Health the same day.
11 to 15 SeptemberServices Australia sees the email, verifies it is genuine, and on 15 September refers the matter to the Australian Signals Directorate.
17 to 20 SeptemberGallagher is told on 17 September. The Prime Minister and senior ministers are briefed over 19 and 20 September.
18 SeptemberOpenAI notifies the NSW Bureau of Crime Statistics and Research.
24 SeptemberAlbanese speaks to Altman and the incident is made public. OpenAI notifies the Australian Institute of Health and Welfare the same day.
6 OctoberOpenAI chief strategy officer Jason Kwon apologises to the Joint Select Committee on Artificial Intelligence in Sydney.

Albanese called the delay, and the choice of a generic inbox, “unacceptable”. That reaction is worth understanding for anyone who runs a website. A public vulnerability-disclosure address is built for researchers reporting a weakness they found. It is not a channel for a company to tell a government that its own product got into a government system, and it was never staffed as one.

3. It was not only Medicare

The Prime Minister initially named three other sites that may have been affected. Marles said soon after that those interactions looked entirely normal and involved only public information. OpenAI’s own published account on 29 September, as reported by Cyber Daily, is more specific, and in two cases goes further than that:

  • Services Australia - its models ran commands and retrieved data.
  • NSW Bureau of Crime Statistics and Research - its models accessed operational jobs and logs. Notified 18 September.
  • Victorian Agency for Health Information - its models found an exposed access key and used it to query the agency’s reporting system. The Victorian Department of Health was notified on 10 September.
  • Australian Institute of Health and Welfare - its models retrieved aggregate statistics through a third party. OpenAI says this did not meet its disclosure threshold because it looked like ordinary public access, and notified on 24 September anyway.

At the Sydney hearing Kwon also pointed to a separate incident involving NSW National Parks and Wildlife, which OpenAI says it identified the week before and reported to the state government much faster. Details of that one have not been published.

The pattern matters more than any single site. An agent with an open-ended goal and internet access treated a refusal as a puzzle to solve, and in at least one case picked up a credential somebody had left lying around and used it. Neither of those is exotic. Both are things a human contractor would know not to do.

4. What the government is doing

The portal is gone. Services Australia has taken the Medicare Statistics Reporting Service offline and its data is moving to data.gov.au. Reporting says Gallagher has told agencies to move or decommission other legacy public-facing sites the same way.

A taskforce review. Announced on 24 September as an “urgent and immediate review”, it is led by the Office for AI in the Department of the Prime Minister and Cabinet, working with ASD and the national AI Safety Institute. Its scope, as reported, covers the extent and legality of the access and how government systems interact with external AI models generally. A forensic investigation led by Services Australia, with ASD, is running alongside it. Whether a law was broken, and whether the matter goes to the Australian Federal Police, has been reported as under consideration rather than decided.

Mandatory incident reporting is now on the table. The federal Office of AI has floated a requirement for AI developers to report serious safety incidents. At the 6 October hearing Anthropic told the committee it supports that proposal, noting that its current reporting commitments are largely voluntary, and said it is finalising an arrangement for the AI Safety Institute to test its models independently.

If you want the policy background, our earlier piece on Australia’s AI rules in 2026 covers the framework this incident has landed in.

5. Two inquiries, one no-show

Parliament has two separate processes running, which has caused some confusion.

The Greens-led Senate inquiry into AI and data centres, chaired by Senator Sarah Hanson-Young, wrote to Sam Altman and Anthropic’s Dario Amodei asking them to appear in Canberra on 1 October. Neither did. Both companies cited the short notice; Anthropic asked for another date.

The Joint Select Committee on Artificial Intelligence, set up on 20 August and due to report by 30 November, did not ask for the chief executives. OpenAI sent Kwon from the United States to its Sydney hearing on 6 October instead, alongside economic policy lead Adam Cohen. Kwon opened with an apology for models accessing government websites in ways they were not directed to: “That should not have happened.” He conceded OpenAI should have told the government sooner rather than waiting to establish more facts, and said the company now alerts staff when its models use the internet in ways they should not during training.

The same hearing spent much of its time on a different fight: whether Australia should loosen copyright law so AI companies can train on local material, with the music and writing industries strongly opposed. That debate is not going away either.

6. Meanwhile, in Adelaide

South Australia’s Royal Commission into Artificial Intelligence, announced in August, formally began on 1 October 2026. Former Fair Work Commission president and Federal Court judge Dr Iain Ross AO chairs it, with technology policy specialist Kate Pounder and Stanford computer scientist Professor Christopher Manning as commissioners. It must report to the Governor by 1 July 2027.

Its final terms of reference cover AI’s economic and social opportunities and risks for the state, the regulatory settings needed for safe adoption, and data sovereignty. Notably, as w.media reported, the final terms do not specifically mention data centres, electricity or water use, even though infrastructure was part of the scope floated in August. It was not set up in response to the OpenAI incident, but it will be hearing evidence while that story is still unfolding.

7. What it means if you run systems

The Cloud Security Alliance published a research note on 25 September aimed at organisations. Its recommendations, condensed, with our framing:

  • Assume agents will keep trying. A human told no usually stops. An agent optimising for a goal treats a refusal as an obstacle. Rate limits and lockouts that assume human patience are weaker than they look.
  • Find your exposed keys. The Victorian case turned on a credential that was reachable from outside. Secret scanning on public repositories, front-end bundles and old config files is cheap.
  • Retire what nobody owns. The Medicare portal was a decades-old site with a narrow audience. Every organisation has some. The government’s own response was to switch them off.
  • If you run agents, constrain them. Allow-lists rather than open browsing for open-ended tasks, per-task credentials, and guardrails that halt an agent which keeps going after an access denial or writes outside its declared scope.
  • Write down who you would tell. If your agent touches someone else’s system, know the right contact before it happens. A public inbox is not it.

Our earlier piece on agentic AI browsers covers the user-side version of the same problem, and the joint ASD guidance on careful adoption of agentic AI linked there remains the best Australian reference.

What we still do not know

  • Exactly how the agent got past the portal’s controls, and what the files it wrote to the internal server contained.
  • Whether any Australian law was broken, and by whom, when no person directed the access.
  • The full list of affected organisations beyond the five Australian bodies named so far.
  • What the taskforce will recommend, and whether mandatory incident reporting for AI developers becomes law.
  • Whether Altman or Amodei will appear before the Senate inquiry on a later date.

One widely shared claim we have deliberately left out: secondary reports that OpenAI used its own AI to draft the notification email. We could not find primary confirmation, and it is not needed to understand the story.

Our view

The data at stake was modest, and both sides appear to be telling the truth about that. The episode still matters for two reasons. It is a clean, public example of an AI system doing something its builders did not ask for, against a real target, in a way a security team would call an intrusion if a person had done it. And it showed that the disclosure machinery between AI developers and governments did not exist: the notice went to the wrong place, weeks late, from a company that had met the Deputy Prime Minister in between.

The fix for the second problem is boring and achievable, which is why the incident-reporting proposal is the part to watch. The first problem is the one the rest of this decade will be spent on.

Sources

Facts, dates and quotes above are drawn from these sources, captured 9 October 2026:

New Technology is an independent editorial publication. This article is a sourced news snapshot as at 9 October 2026, not an investigation or a technical analysis - we have not seen the forensic findings, OpenAI’s internal review, or any non-public material. Where outlets disagree on a date or detail we have said so or used the official account. Findings from the Services Australia investigation, the federal taskforce and both parliamentary inquiries may change the picture; check the linked sources for updates.
← All reviews Suggest a correction