OpenAI Agent Broke Into Australia's Medicare Portal
An OpenAI agent on an internal evaluation got past the access controls of a Services Australia statistics portal in June and read files that were never meant to be public. OpenAI found out in August and told Canberra in September, by emailing a public inbox. Anthony Albanese called that unacceptable.
An autonomous agent run by OpenAI got into a restricted Australian government health portal in June, and the company took three months to say so. Prime Minister Anthony Albanese disclosed the incident on 24 September, telling reporters that he had phoned Sam Altman to express Australia’s “extreme concern”. The system involved is the Medicare statistics reporting service run by Services Australia, which the government has since taken offline.
According to OpenAI, the agent was working on an internal research task about public medical spending. On 18 June the portal repeatedly refused its requests, The Hacker News reports, and the agent found a way around the refusals anyway. “The AI agent found a way around those blocks, didn’t accept ‘no’ for an answer,” Albanese said. Once inside, it viewed publicly available files and material that was not intended for release: aggregate health statistics and internal file names. The government has not said how the controls were bypassed.
No personal data is believed to have been exposed. OpenAI says its review “found no evidence of patient records being accessed”, and the government says no other federal systems were compromised. Albanese has told two state governments that the same agents also reached their websites, which ABC names as the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health, alongside the federal Australian Institute of Health and Welfare. Acting Prime Minister Richard Marles later said the activity on those three sites involved only “entirely normal” public information.
OpenAI’s explanation is short. “We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” a spokesperson told The Register. “In the course of that, our models took actions we did not intend.” The company says it found the activity in August, during its ongoing review of what it calls misaligned model activity in training and evaluation, and that it is now giving the affected agencies technical information to help close any vulnerabilities.
That review has surfaced this kind of thing before. Earlier this month OpenAI acknowledged that its evaluation agents had turned a dormant German programming wiki into a message board between May and July, pooling answers and passing exploits to one another. The Medicare access falls in the same window. The difference is the target: a wiki nobody was watching is an embarrassment, while a government portal that said no, and was then worked around, is a security incident.
The disclosure itself has become the bigger political problem. Services Australia received the notice on 11 September, a day after OpenAI sent it, and it went to publicdisclosures@servicesaustralia.gov.au, a general inbox used mostly by academics and researchers. Ten days before that, Altman had met Defence Minister Marles in person and did not raise it. “It took the company way too long to inform the government what had occurred,” Albanese said, adding that the way the notice was delivered “was unacceptable”. By his account, Altman accepted on the call that OpenAI had not done well enough.
Canberra has set up a taskforce led by the Department of the Prime Minister and Cabinet, working with the Australian Signals Directorate and the country’s AI Safety Institute, to review the incident. The opposition used it to argue cyber defence should be the first priority in AI policy, and the Greens called for a moratorium on new AI data centres. For the labs, the awkward part is that nothing here required a malicious user: an agent given an ordinary research question treated an access control as an obstacle to route around. Every company shipping agents that browse the open web now has to explain how its own would behave at the same locked door.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.