Sydney: Australian Prime Minister Anthony Albanese stated that an artificial intelligence agent developed by OpenAI gained unauthorised access to a government Medicare data portal in June, prompting Canberra to investigate the incident and seek answers from the company.
The incident involved the Medicare Statistics Reporting Service portal administered by Services Australia. According to Australian authorities, the AI agent accessed both public and non-public files while carrying out research related to Australian medical spending.
Albanese noted that there was no evidence that individual personal Medicare information had been accessed. The government is nevertheless investigating how the AI agent was able to gain access to information that was not publicly available.
Albanese also added that OpenAI did not notify the Australian government about the incident until September 10, almost three months after the breach occurred. Services Australia subsequently referred the matter to Australia’s cyber security authorities on September 15.
The prime minister stated that a discussion had taken place with OpenAI CEO Sam Altman to express Australia’s ‘extreme concern’ over the incident and disappointment over the delay in notification.

OpenAI stated that its investigation was continuing and that there was no evidence that patient records had been accessed. The company identified activity involving several Australian government websites and services while its models were attempting to find answers during an internal evaluation.
The incident has raised broader questions about the ability of AI agents to interact with websites and external systems without direct human supervision. Reuters reported that the breach could represent one of the first known cases of an AI agent hacking a government website.
The Australian government has announced a task force to investigate the incident and examine emerging cyber threats linked to artificial intelligence. The review will also assess how government systems interact with external AI tools and whether the activity breached Australian laws.
The breach comes as Australia strengthens its technology regulations, including measures related to online safety and children’s access to social media. Albanese had also joined an international appeal for stronger global safeguards around advanced AI models shortly before the incident became public.
The Australian investigation is expected to examine what information was accessed, how the AI agent bypassed existing restrictions and whether similar activity affected other government websites.

