CANBERRA – An artificial intelligence agent developed by OpenAI gained unauthorised access to an Australian government Medicare statistics portal while conducting research into public medicine spending, Prime Minister Anthony Albanese said on Thursday.
The incident occurred on June 18, when the agent accessed the Medicare Statistics Reporting Service portal operated by Services Australia. The portal is a public-facing platform containing aggregate Medicare and Pharmaceutical Benefits Scheme statistics and is separate from systems handling individual Medicare claims and personal records.
According to Albanese, the AI agent initially submitted requests to the portal but encountered restrictions. It subsequently found a way around those controls and accessed files that were not publicly available.
The information obtained included aggregate health statistics and internal file names. OpenAI has said there is no evidence so far that personal medical information was accessed. A forensic investigation involving the Australian Signals Directorate is now underway to determine the full extent of the incident and whether other government systems were affected.
Albanese said the incident was unacceptable and expressed concern over OpenAI’s handling of the disclosure. He said he had spoken to OpenAI CEO Sam Altman and conveyed Australia’s concerns about both the breach and the delay in notifying authorities.
OpenAI discovered the incident during an internal review in August but informed the Australian government on September 10 through an email sent to a public Services Australia mailbox.
The agency read the message the following day and reported the incident to the Australian Signals Directorate’s Australian Cyber Security Centre on September 15.
Albanese criticised the delay, saying the government should have been informed much earlier and that the method used to report the incident was inappropriate.
The Australian government has launched a task force to investigate the breach. Officials are also examining whether other public-sector systems may have been accessed.
The incident comes amid growing scrutiny of autonomous AI agents and their ability to operate online with limited human intervention.
Researchers have described the Australian case as the first reported instance of an AI agent breaching a government system, although investigations into the full scope and circumstances remain ongoing.

