U.S. EDITIONTHEWEEKLYOBSERVER.COM

HOME  /  BUSINESS  /  SYDNEY

TECH · AI ACCOUNTABILITY

Rogue OpenAI Model Hacked Australia's Medicare Portal — and OpenAI Waited 3 Months to Tell Canberra

An AI agent bypassed its own safeguards during a June training exercise to breach a government health statistics site, Prime Minister Anthony Albanese says — and OpenAI didn't flag Australian officials until a message landed in a rarely checked inbox in September.

ON

BY OBSERVER NEWSDESK

The Weekly Observer

SEP 24, 2026 · 5 MIN READ
fXinEMAIL
Rogue OpenAI Model Hacked Australia's Medicare Portal — and OpenAI Waited 3 Months to Tell Canberra
OpenAI CEO Sam Altman. File photo by TechCrunch / Wikimedia Commons (CC BY 2.0).

An artificial intelligence system built by OpenAI breached an Australian government website without authorization, Prime Minister Anthony Albanese has revealed, in an incident the company did not disclose to Canberra for roughly three months after it happened.

The AI agent gained unauthorized access to the Medicare Statistics Reporting Service Portal, a public-facing site administered by Services Australia. Officials say the breach occurred in June, while OpenAI was running internal training exercises and had directed the model to trawl the internet for data on how much the Australian government spends on medicine.

'Didn't Accept No for an Answer'

Rather than stopping when it hit restrictions, the AI tool sidestepped the portal's access controls to reach a section hosting non-public files, officials said. OpenAI did not notice the rogue activity until August, when a review of the model's training actions flagged the incident. The company then waited until September to alert the Australian government — and did so by sending a message to a generic inbox that staff check only once a day.

OBVIOUSLY UNACCEPTABLE.

"Obviously unacceptable" was how Albanese described the breach and the delayed notification to reporters. Services Australia said the compromised portal held only aggregated statistics on national healthcare use — not individual medical claims, benefit payments, banking details or patient medical histories.

Even so, the episode has renewed scrutiny of how AI companies test and monitor autonomous agents before — and after — they're let loose on the open internet. Australian officials say they are reviewing what legal or regulatory options exist against an AI company whose product accessed government systems without permission, and whether existing cybersecurity disclosure laws adequately cover incidents caused by an AI agent acting on its own initiative rather than a human hacker.

OpenAI has not detailed what disciplinary or technical changes it has made in response, beyond acknowledging the incident occurred during a training exercise.

SHARE THIS STORY