In June, an AI agent from OpenAI gained unauthorized access to a statistics portal operated by Australia’s Medicare. Prime Minister Anthony Albanese called the incident unacceptable and criticized OpenAI for not reporting it until September 10. A task force is investigating.
The portal in question is the Medicare Statistics Reporting Service, a Services Australia portal containing aggregated data on healthcare utilization. The agent encountered restricted files there while researching public healthcare spending. According to Albanese, the available evidence does not point to a broader network compromise.
Speaking in New York, where he is attending the UN General Assembly, the Australian prime minister left little doubt about his assessment. “There were blocks clearly which were coming back telling the AI agent ‘no’. The AI agent found a way around those blocks – didn’t accept no for an answer,” he told reporters.
Defense Minister Richard Marles emphasized that the portal does not contain individual expense reports, benefit payments, bank details, or medical records of the 27 million Australians. OpenAI says it found no evidence that patient data was accessed. However, the company acknowledges that its models “took actions we did not intend” while attempting to search for answers on multiple Australian government websites.
Reporting requirements and detection under scrutiny
The fact that it took until September 10 for a report to be filed at all is a major concern for the Australian government. Albanese expressed “extreme concern” to OpenAI CEO Sam Altman. The investigation is also examining why the government systems did not detect the breach on their own. Three other healthcare-related government websites may have been compromised, though this has not been confirmed.
According to reports in Australia, the breach involved not only aggregated statistics but also internal filenames. Some sources report that the agent modified files on an internal server, but that is still part of the investigation.
AI agents have recently been successfully gaining access to companies, in a manner that closely resembles cyberattacks. The Hugging Face incident, in which OpenAI agents gained access to the platform to learn more about training, is the best-known example. Anthropic recently disclosed a fourth cyber incident, in which a Claude model gained administrator access to a third-party system during an evaluation and modified system settings. Google and Meta have also previously reported incidents involving agents accessing external systems.
The Australian government has established a task force that, in addition to investigating the breach, is assessing whether current network security is sufficient. The investigation is ongoing.
Tip: Security surrounding AI model development must improve drastically, but how?