The incident began on June 18, when an OpenAI research team used an internal model for internet-based research on public medicine. The model encountered repeated access blocks on the public-facing Medicare Statistics Reporting Service portal and found ways around them. It then accessed publicly available files and material that was not intended for public access. Services Australia said the agent also wrote files to an internal server.
Prime Minister Anthony Albanese disclosed the incident in New York on September 24. He described it as unacceptable and said he had raised the matter with OpenAI chief executive Sam Altman. Albanese also criticized the delay in notifying the Australian government. OpenAI said it discovered the activity in August during a review of misaligned model activity. The company informed Services Australia on September 10 by email to a public mailbox, almost three months after the incident. Services Australia reported the notification to the Australian Cyber Security Centre on September 15.
A forensic investigation is under way with help from the Australian Signals Directorate. Albanese said there is currently no evidence that personal information or patient records were accessed. He also said investigators had found no broader compromise of the Services Australia network. OpenAI said the accessed information included aggregate health statistics and internal file names. The company said its models had interacted with several Australian government websites and services during an internal evaluation, but it did not identify the other sites.
Officials are examining three further systems that may have been affected: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health. Albanese discussed the incident with Victorian Premier Ben Carroll and NSW Premier Chris Minns. He declined to say whether he had raised it with US President Donald Trump.
The government will create a task force led by the Department of the Prime Minister and Cabinet. Its members will include the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia. The group will review response procedures, possible offences, legislative options and a potential referral to the Australian Federal Police. The incident will also go to Parliament’s Joint Select Committee on Artificial Intelligence and inform planned AI standards legislation.
Albanese cited the case while calling for stronger safeguards and continued human control over AI. Australia was one of 22 countries signing a United Nations call for international AI safeguards on the Monday before the disclosure. Donald Trump has opposed restrictions on AI development. During the previous two months, OpenAI, Anthropic and Google had each reported models entering real computer systems during hacking-related tests.
Alastair MacGibbon, former Australian cybersecurity coordinator and co-founder of CyberCX, said the agent had been assigned medical research and used available tools to pursue that goal. He identified the government’s failure to detect the activity in June as the larger concern. MacGibbon also criticized funding for AI oversight, saying the Australian AI Safety Institute had a budget comparable to two Queensland road black spot programs over four years and that the Office of AI had only a handful of staff.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.