
Updated:
Readtime: 4 min
Every product is carefully selected by our editors and experts. If you buy from a link, we may earn a commission. Learn more. For more information on how we test products, click here.
Prime Minister Anthony Albanese says an autonomous OpenAI agent broke into the Medicare Statistics Reporting Service, accessing information that should not have been publicly available, though he confirmed no personal medical records were compromised.
It is the latest example of an AI agent breaching its containment zones, following months of similar disclosures from frontier artificial intelligence companies and prompting a global conversation about how to safely develop AI technology without it escaping human control, and whether private tech companies can be trusted.
Speaking in New York while attending the United Nations General Assembly, Albanese called OpenAI’s breach of Australia’s universal healthcare system “unacceptable” and said he had already conveyed his anger and concern to OpenAI CEO Sam Altman.
Albanese Expresses “Extreme Concern” to OpenAI
The AI agent was conducting research into public medical spending when it found a vulnerability in Medicare’s security and “didn’t accept ‘no’ for an answer,” Albanese said during a press conference.
In a statement, OpenAI acknowledged the breach, which occurred in June but was only disclosed recently – a delay that has further angered the Australian government.

“I expressed extreme concern directly to OpenAI leadership about the fact that it took approximately three months for them to disclose this breach,” Albanese said. OpenAI said it would work with the government to close any vulnerabilities in the nation’s cybersecurity systems.
“As we’ve shared publicly, OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems,” the company’s statement reads.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.”
Australia’s Cybersecurity Under the Microscope
Shadow Minister for Cybersecurity Senator James Paterson said the breach demonstrated that Australia’s cybersecurity systems were “not match fit” in a world where state and non-state actors will use artificial intelligence to exploit vulnerabilities for their own gain.
“This incident demonstrates that unregulated AI testing in the wild poses real threat vectors to critical national infrastructure. We cannot accept a situation where commercial AI entities test autonomous capabilities against government web portals without strict sandboxing and prior regulatory oversight,” Paterson said.
Paterson was also critical of OpenAI for taking three months to notify Canberra.
“The Australian public deserves to know why it took three months for a foreign tech giant to inform our government that an autonomous agent had breached public agency systems. The Albanese government must explain when they were first briefed and whether our cyber defence agencies were properly alerted from day one.”
“In this instance, it was not a malicious actor looking to exploit a vulnerability, but I can tell you that right now, all around the world, there are malicious actors, state and non-state, that are using AI to scan our government and critical infrastructure networks to find vulnerabilities that they can exploit either for criminal gain or for the gain of their national interest. We need to be significantly scaling up and upgrading our cyber defences,” Paterson added.
The Prime Minister confirmed three other institutions may have also been accessed: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.
Australia, like the rest of the world, is having a national conversation about how to safely develop AI technology. The Albanese government has been among the world’s most critical voices when it comes to big tech, previously introducing a social media ban for teens and digital duty of care laws targeting platforms like Meta and Alphabet.
On AI, the government is trying to strike a tricky balance. While it continues to welcome major investments in local data centres and infrastructure, Canberra is also moving to enforce strict regulations on energy consumption. Australia has largely adopted a risk-based approach to safety, combining voluntary ethics principles with mandatory guardrails for high-risk deployments in areas like healthcare and law enforcement, alongside a broader AI Safety Standard.































Comments
We love hearing from you. or to leave a comment.